Impact
dataCycle-CORE contains a public endpoint that serves attached text files directly when a DataLink UUID is supplied. The system does not enforce expiration or authentication checks, meaning any user who knows or guesses a UUID can download the file regardless of the link’s intended validity, the user’s authentication status, or the normal access control flow. As a result, confidential or restricted data can be disclosed to unauthorized parties, potentially violating privacy and data protection policies.
Affected Systems
The affected product is dataCycle-CORE from datacycle-engine. Versions up to and including 25.07.3 are impacted; all releases thereafter incorporate the fix referenced in the vendor advisory.
Risk and Exploitability
The CVSS score of 7.5 reflects a high severity vulnerability with medium to high exploitation potential. The EPSS value is unavailable, and the issue is not listed in the CISA KEV catalog, though the public nature of the endpoint makes it readily exploitable over the network. The likely attack vector is remote, involving an unauthenticated HTTP request to the exposed file URL; an attacker could obtain the UUID from leaked emails, forwarded messages, or logs. Whether the link is expired or access is normally denied does not prevent data retrieval, so the risk persists until the patch is applied.
OpenCVE Enrichment