CVE-2026-32806: Datacycle-Engine Datacycle-Core
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated user can request arbitrary partials or helper-backed render functions through /remote_render. The endpoint does not restrict which partial can be rendered and does not apply controller-specific authorization before rendering the selected view. This enables a low-privileged user to retrieve server-side rendered admin content that is otherwise hidden by navigation and route checks. On the test instance, a Standard user was able to retrieve the PostgreSQL admin dashboard stats even though /admin itself redirected away. This is patched in 26.06.08.
Affected products
- Datacycle-Engine Datacycle-Core: up to and including 25.07.3
Published 2026-07-20. Last modified 2026-07-21.