translation state changes. This is patched in version 26.06.08.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Datacycle-engine
Datacycle-engine datacycle-core |
|
| Vendors & Products |
Datacycle-engine
Datacycle-engine datacycle-core |
Mon, 20 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Jul 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application exposes server-side state changes through `GET` routes. Because browsers automatically send cookies on same-site top-level navigation and Rails does not apply CSRF protections to `GET`, an attacker can force a logged-in victim to modify application state by embedding a link, image, iframe, or redirect to one of these endpoints. This was confirmed on the target with a normal `Standard` account: a cross-site-style `GET` to `watch_lists/:id/add_item?thing_id=...` inserted content into a watch list with no CSRF token. Additional `GET` mutation routes exist in the codebase, including user impersonation for authorized admins and cache or translation state changes. This is patched in version 26.06.08. | |
| Title | dataCycle State-Changing GET Endpoints Enable CSRF | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-20T19:05:22.754Z
Reserved: 2026-03-16T17:35:36.697Z
Link: CVE-2026-32823
Updated: 2026-07-20T19:04:58.011Z
Status : Deferred
Published: 2026-07-20T17:17:05.877
Modified: 2026-07-21T19:35:17.130
Link: CVE-2026-32823
No data.
OpenCVE Enrichment
Updated: 2026-07-30T19:15:04Z