CVE-2026-32824 Details
Description
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a low-privileged authenticated API user can supply `forwardToUrl` and `redirectUrl` values when triggering password reset or confirmation flows. Those values are then embedded into the outgoing email workflow without host allowlisting. This creates two related abuse paths: - password reset or confirmation links can be sent to a victim with the token already attached to an attacker-controlled `forwardToUrl` - after a legitimate password reset completes, the browser is redirected to attacker-controlled `redirectUrl` In practice, this can be used for phishing, token capture, confirmation hijacking, or steering a victim from a trusted email into an attacker domain. This is patched in version 26.06.08.
A vulnerability exists in dataCycle-CORE versions prior to 25.07.3, allowing low-privileged authenticated API users to manipulate `forwardToUrl` and `redirectUrl` values during password reset or confirmation processes. These values are sent in the outgoing emails without any host allowlisting. This vulnerability creates two related abuse paths: first, an attacker can send a victim a password reset or confirmation link with a token attached, directing them to an attacker-controlled `forwardToUrl`; second, after a legitimate password reset, the victim's browser is redirected to an attacker-controlled `redirectUrl`. This could be exploited for phishing, token capture, confirmation hijacking, or redirecting a victim from a trusted email to an attacker-controlled domain.
Users can upgrade to dataCycle-CORE version 26.06.08 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 20, 2026CISA-ADP
Assessed Jul 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/datacycle-engine/dataCycle-CORE/security/advisories/GHSA-8jfx-wpjg-hf38 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| datacycle-engine dataCycle-CORE | <= 25.07.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 20, 2026 | CVE Modified | CISA-ADP |
| Jul 20, 2026 | New CVE Received | [email protected] |
Volerion