PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-65980 chartbrew CVE debrief

CVE-2026-65980 is a high-severity vulnerability in Chartbrew, an open-source web application for creating charts from database and API data. The issue, fixed in version 5.2.3, allows an attacker to execute arbitrary ClickHouse SQL by exploiting the ClickHouse protocol's lack of escapeBackslash option in variable binding. Public dashboards can expose this vulnerability without authentication, potentially leading to data disclosure or access to internal network resources if the database configuration permits.

Vendor
chartbrew
Product
Unknown
CVSS
HIGH 7.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-21
Original CVE updated
2026-09-28
Advisory published
2026-09-21
Advisory updated
2026-09-28

Who should care

Defenders responsible for Chartbrew instances, especially those with public dashboards or database configurations that permit access to internal resources, should assess exposure and prioritize remediation.

Why it matters

CVE-2026-65980 is a high-severity vulnerability in Chartbrew that allows arbitrary ClickHouse SQL execution. Defenders should prioritize verifying exposure, especially for public dashboards, and upgrade to version 5.2.3 or later. Monitoring for suspicious activity is also recommended. The vulnerability's impact requires verification from official sources, and evidence is limited to CVE and NVD records.

  • Potential data disclosure through arbitrary SQL execution
  • Possible access to internal network resources if database configuration permits
  • Need for verification of Chartbrew instance exposure and version
  • Requirement for monitoring suspicious SQL activity

Technical summary

The Chartbrew application, prior to version 5.2.3, does not properly handle variable binding in its ClickHouse protocol implementation. Specifically, the applySqlVariables() function is called without enabling the escapeBackslash option. This allows an attacker to supply a backslash before a quote, potentially leading to arbitrary ClickHouse SQL execution. The vulnerability can be exploited through public dashboards without authentication, and successful exploitation can result in data disclosure or, if the database configuration permits, access to files or internal network resources.

Defensive priority

Defenders should prioritize verifying exposure of public dashboards, inventorying Chartbrew instances, and upgrading to version 5.2.3 or later. Additional monitoring for suspicious SQL activity may be necessary.

Recommended defensive actions

  • Verify exposure of public dashboards and inventory Chartbrew instances
  • Upgrade to Chartbrew version 5.2.3 or later
  • Monitor for suspicious SQL activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its impact, and the fix in version 5.2.3. GitHub references offer additional context on the patched version and advisory. Defenders should verify exposure of public dashboards, especially those with potential database access, and monitor for suspicious SQL activity. Evidence is limited to CVE and NVD records, so further verification is necessary.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-65980 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-65980

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-65980 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-65980

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.