NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-32824
Summary

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a low-privileged authenticated API user can supply `forwardToUrl` and `redirectUrl` values when triggering password reset or confirmation flows. Those values are then embedded into the outgoing email workflow without host allowlisting. This creates two related abuse paths:
- password reset or confirmation links can be sent to a victim with the token already attached to an attacker-controlled `forwardToUrl`
- after a legitimate password reset completes, the browser is redirected to attacker-controlled `redirectUrl`

In practice, this can be used for phishing, token capture, confirmation hijacking, or steering a victim from a trusted email
into an attacker domain. This is patched in version 26.06.08.

Publication Date July 21, 2026, 2:17 a.m.
Registration Date July 21, 2026, 4:29 a.m.
Last Update July 21, 2026, 3:16 a.m.
CVSS3.1 : HIGH
スコア 7.3
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
攻撃元区分(AV) ネットワーク
攻撃条件の複雑さ(AC)
攻撃に必要な特権レベル(PR)
利用者の関与(UI)
影響の想定範囲(S) 変更なし
機密性への影響(C)
完全性への影響(I)
可用性への影響(A) なし
Related information, measures and tools
Common Vulnerabilities List