Impact
In dataCycle-CORE versions up to 25.07.3 the /remote_render endpoint allows any authenticated user to request arbitrary partials or helper‑backed render functions. The endpoint does not enforce controller‑specific authorization, so a user with limited permissions can retrieve server‑side rendered views that are normally hidden by navigation and route checks. This flaw permits the exposure of privileged admin content, such as PostgreSQL dashboard statistics, to unauthorized users, violating confidentiality and potentially leading to further lateral movement within the application.
Affected Systems
Affected systems are installations of the dataCycle data management system, specifically the dataCycle‑CORE component prior to version 26.06.08. The vulnerability applies to all releases through 25.07.3 and was patched in 26.06.08. their version and upgrade accordingly.
Risk and Exploitability
The CVSS score of 7.5 indicates moderately high risk. The EPSS score is < 1%, and the vulnerability is not listed in CISA KEV. The likely attack vector is an authenticated low‑privileged user exploiting the unauthenticated rendering capability; the account but does not need elevated rights. Once accessed, the attacker can retrieve hidden admin content, potentially exposing sensitive data and aiding further attacks. Prompt remediation is recommended to mitigate this medium‑to‑high risk.
OpenCVE Enrichment