CyberRota
Back to database

CVE-2026-35514

MEDIUM · CVSS 6.5 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published: 2026-04-30 · Last synced: 2026-05-30

CyberRota Analysis

Detaylı analiz gerekiyor.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-35514
Severity
MEDIUM
CVSS
6.5
EPSS
0.13%

Original NVD Description

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, the endpoint POST /user/invited does not validate any invite token, authentication header, or session. Any unauthenticated attacker can call this endpoint directly to create a fully active account and receive a valid JWT — even when the instance has existing users and signupRestricted is enabled. This bypass is distinct from the normal registration endpoint (POST /user) which enforces signupRestricted and sets active: false pending verification. This issue has been patched in version 5.0.0.