dataCycle-CORE Public DataLink Text File Download Vulnerability Allowing Unauthorized Access

Vulnerability

A vulnerability in dataCycle-CORE versions prior to 25.07.3 allows unauthorized access to attached text files via DataLink UUIDs. The issue arises because the public route does not validate link expiration or authentication, enabling anyone with a UUID to download files even through expired or previously logged email links. This flaw is exacerbated by the mailer embedding direct file URLs, which can be leaked or forwarded.

Impact

Exploitation of this vulnerability allows unauthorized users to access and download confidential text files linked through DataLink UUIDs, bypassing normal access controls and link validity checks.

Remediation

Users can upgrade to dataCycle-CORE version 26.06.08 to address this vulnerability.

Added: Jul 20, 2026, 11:46 PM
Updated: Jul 20, 2026, 11:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.8
remediation
0.0
relevance
9.9
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.