HarborGuard / CVE
Back to search
HIGHCVE-2026-27005Published Modified CNA GitHub_M

CVE-2026-27005: Chartbrew: SQL injection in date-type variable handling (applyMysqlOrPostgresVariables)

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.3, an unauthenticated attacker can inject arbitrary SQL into queries executed against databases connected to Chartbrew (MySQL, PostgreSQL). This allows reading, modifying, or deleting data in those databases depending on the database user's privileges. This issue has been patched in version 4.8.3.

Metrics

CVSS v4.0
8.8
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • chartbrew / chartbrew
    < 4.8.3
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
CVE-2026-27005: Chartbrew: SQL injection in date-type variable handling (applyMysqlOrPostgresVariables) | HarborGuard CVE