Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

Chartbrew version prior to 4.8.3 allows database data access without login

CVE-2026-27005
Summary

An attacker without a login can access and modify data in databases connected to Chartbrew if they know how to write SQL commands. This is fixed in version 4.8.3, so update to this version or later to prevent this.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
depomo chartbrew <= 4.8.3 –
Original title
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.3, an unauthenticated attacker can inject arbitra...
Original description
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.3, an unauthenticated attacker can inject arbitrary SQL into queries executed against databases connected to Chartbrew (MySQL, PostgreSQL). This allows reading, modifying, or deleting data in those databases depending on the database user's privileges. This issue has been patched in version 4.8.3.
nvd CVSS4.0 8.8
Vulnerability type
CWE-89 SQL Injection
Published: 6 Mar 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026