These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The CVE record was published on 2026-07-20T17:17:06.140Z and has not been modified since then. CVE-2026-32825 is a data management system vulnerability in dataCycle-CORE, affecting versions before and including 25.07.3. The vulnerability allows unlimited password guesses against both the browser login flow and the JSON login endpoint, creating a direct online password-guessing risk. Successful guessing yi [truncated]
A vulnerability in dataCycle-CORE, a data management system, allows low-privileged authenticated API users to supply malicious URLs for password reset or confirmation flows. This can lead to phishing, token capture, confirmation hijacking, or steering victims from trusted emails to attacker domains. The vulnerability exists in versions before and including 25.07.3 of dataCycle-CORE. An attacker can exploi [truncated]
A cross-site request forgery vulnerability exists in dataCycle-CORE, a data management system, before and including version 25.07.3. The application exposes server-side state changes through `GET` routes, allowing an attacker to force a logged-in victim to modify application state by embedding a link, image, iframe, or redirect to one of these endpoints. This was confirmed with a normal `Standard` account [truncated]
CVE-2026-32821 is a high-severity vulnerability in dataCycle-CORE, a data management system. The vulnerability allows authenticated API users to evaluate permissions as a different user and potentially expose collections through the API. Additionally, it offers routes for adding and removing items from collections without proper authorization checks, creating a likely cross-user modification path. Affecte [truncated]
A high-severity directory traversal vulnerability exists in dataCycle-CORE, a data management system, before and including version 25.07.3. The module handling core processing and framework rules accepts attacker-controlled path segments and only runs them through the Rails HTML sanitizer, which does not remove directory traversal sequences. This allows an unauthenticated attacker to traverse out of the i [truncated]
A MEDIUM severity vulnerability was found in dataCycle-CORE, a data management system, which allows Standard users to enumerate other users' names and email addresses through the `/users/search` endpoint. This issue was present before and including version 25.07.3. The vulnerability has a CVSS score of 4.3 and affects internal staff addresses, full names, and the existence of guest and external test accou [truncated]
In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated user can request arbitrary partials or helper-backed render functions through /remote_render. The endpoint does not restrict which partial can be rendered and does not apply controller-specific authorization before rendering the selected view. This enables a low-privileged us [truncated]
A reflected DOM XSS vulnerability exists in dataCycle-CORE, a data management system, before and including version 25.07.3. The issue allows unauthenticated attackers to inject arbitrary HTML into flash notifications on public routes, which can then be delivered to users via a crafted link. This can impact users hosting public-facing instances. The vulnerability is caused by the use of `innerHTML` in the [truncated]
In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, anyone with a DataLink UUID can fetch the attached text file directly, even if the link is expired, the caller is unauthenticated, or the normal show flow would have denied access. This vulnerability allows unauthorized access to sensitive data and can be exploited through leaked, forwarded, l [truncated]