Executive brief
dataCycle is a data management system used for storing and distributing corporate information. A security flaw allows standard users to search for and view the names and email addresses of other employees and guest accounts, even if they are not authorized to see those profiles. This could lead to the exposure of internal staff directories and the identification of external partner accounts.
Technical details
An improper authorization vulnerability (CWE-285) exists in the dataCycle-CORE module handling framework rules. While direct access to user profiles is restricted, the `/users/search` endpoint does not properly enforce these permissions for authenticated 'Standard' users. An attacker with low-level credentials can perform network-based requests to this endpoint to enumerate full names, email addresses, and the existence of guest or external test accounts. The issue is present in versions up to and including 25.07.3 and is addressed in version 26.06.08.
Affected products
- datacycle-engine dataCycle-CORE <= 25.07.3
Timeline
- 2026-06-24: advisory: Initial GitHub advisory published
- 2026-07-20: disclosed: NVD publication date