Impact
The flaw resides in dataCycle-CORE’s "/users/search" endpoint, where the server does not enforce proper permission checks for Standard role users. As a result, any authenticated Standard user can request the list of all registered users and receive their full names and email addresses. This data disclosure can reveal internal staff contact details and the presence of guest or test accounts, creating potential security and privacy risks.
Affected Systems
The affected product is dataCycle-CORE, developed by datacycle‑engine, and all releases up to and including version 25.07.3 are impacted. The vulnerability is triggered by any authenticated user with a Standard role who invokes the "/users/search" endpoint. No other product variants or versions are listed as affected.
Risk and Exploitability
The CVSS score of 4.3 places the vulnerability in the moderate range, but the EPSS score of less than 1% indicates that exploit attempts are currently rare. The flaw is not listed in the CISA KEV catalog, illustrating that it has not yet been observed in widespread exploitation. Because access to the search endpoint requires the user to be authenticated as at least a Standard role, the threat surface is limited to insiders or compromised accounts rather than external, unauthenticated users. Nonetheless, an attacker who can acquire a Standard credential could enumerate personnel and contact information, potentially enabling social engineering or phishing campaigns.
OpenCVE Enrichment