datacycle-engine dataCycle-CORE
- <= 25.07.3
A vulnerability in dataCycle-CORE versions prior to 25.07.3 allows unauthorized access to attached text files via DataLink UUIDs. The issue arises because the public route does not validate link expiration or authentication, enabling anyone with a UUID to download files even through expired or previously logged email links. This flaw is exacerbated by the mailer embedding direct file URLs, which can be leaked or forwarded.
Exploitation of this vulnerability allows unauthorized users to access and download confidential text files linked through DataLink UUIDs, bypassing normal access controls and link validity checks.
Users can upgrade to dataCycle-CORE version 26.06.08 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.