Junglewise Threat Intelligence

CVE-2026-32824: datacycle-engine dataCycle-CORE open redirect in password reset flow

CVE-2026-32824 · Severity: high · CVSS 7.3 · Published 2026-07-20

Technologies: dataCycle-Engine dataCycle-CORE. Vendors: dataCycle-Engine.

Executive brief

dataCycle is a data management system used for centralizing and distributing corporate data. A security flaw in its core processing module allows attackers to manipulate password reset and account confirmation emails. This can lead to attackers stealing user login tokens, hijacking accounts, or redirecting employees to malicious websites, potentially compromising sensitive business data.

Technical details

A URL redirection vulnerability (CWE-601) exists in dataCycle-CORE's module handling core processing and framework rules. A low-privileged authenticated API user can provide arbitrary values for the `forwardToUrl` and `redirectUrl` parameters during password reset or confirmation requests. Because the application lacks host allowlisting, these attacker-controlled URLs are embedded into outgoing system emails. This allows an attacker to capture sensitive reset tokens by appending them to the `forwardToUrl` or perform phishing by redirecting users to a malicious site via `redirectUrl` after a legitimate action. The vulnerability is patched in version 26.06.08.

Affected products

  • datacycle-engine dataCycle-CORE <= 25.07.3

Timeline

  • 2026-06-24: advisory: GitHub Security Advisory published
  • 2026-07-20: disclosed: CVE published to NVD

References

Related threats