SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-32807

HIGH · CVSS 7.5 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The dataCycle-CORE module, prior to version 25.07.3, allows unauthorized access to attached text files via DataLink UUIDs, even if the links are expired or the user is unauthenticated. This vulnerability can lead to unauthorized data exposure, as any leaked or forwarded email containing the direct file URL can be exploited. Organizations using dataCycle for data management should prioritize patching this vulnerability to protect sensitive information from unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-32807
Severity
HIGH
CVSS
7.5
EPSS
0.29%

Original NVD Description

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, anyone with a DataLink UUID can fetch the attached text file directly, even if the link is expired, the caller is unauthenticated, or the normal show flow would have denied access. Because the route is public and the mailer embeds the direct file URL, any leaked, forwarded, logged, or stale email link can continue to expose the attachment.