Unrated severityNVD Advisory· Published Jul 20, 2026· Updated Jul 20, 2026
dataCycle User Directory Enumeration Via /users/search
CVE-2026-32819
Description
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a Standard user can enumerate other users' names and email addresses through /users/search, even though direct access to those user profiles is denied. This leaks internal staff addresses, full names, and existence of guest and external test accounts.
Affected products
1- Range: <=25.07.3
Patches
Vulnerability mechanics
References
1- github.com/datacycle-engine/dataCycle-CORE/security/advisories/GHSA-c4wj-q23r-mq2qmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.