Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-32825: CWE-307: Improper Restriction of Excessive Authentication Attempts in datacycle-engine dataCycle-CORE

0
High
VulnerabilityCVE-2026-32825cvecve-2026-32825cwe-307
Published: 07/20/2026 (07/20/2026, 16:15:37 UTC)
Source: CVE Database V5
Vendor/Project: datacycle-engine
Product: dataCycle-CORE

Description

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application accepts unlimited password guesses against both the browser login flow and the JSON login endpoint. The source code enables Devise's `:lockable` module on the user model but explicitly disables both lock and unlock strategies, and no request throttling or rate-limiting layer was identified in the Rails code. This creates a direct online password-guessing risk: - valid user accounts can be attacked continuously without temporary lockout - the same weakness is reachable through both `/users/sign_in` and `/api/v4/auth/login` - successful guessing yields a normal session cookie in the HTML flow or a fresh JWT in the API flow - the API endpoint is especially attractive for automation because it requires no CSRF token This has been patched in version 26.06.08.

CVSS v3.1

Score 7.3high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Affected software

GitHub Actionsmore threats →ai
datacycle-engine/dataCycle-CORE
pkg:github/datacycle-engine/dataCycle-CORE
Affected versions
<=25.07.3

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/20/2026, 16:57:08 UTC

Technical Analysis

CVE-2026-32825 is an improper restriction of excessive authentication attempts vulnerability (CWE-307) in dataCycle-CORE, a data management system. Versions up to 25.07.3 allow unlimited password guesses on both the HTML login flow (/users/sign_in) and the JSON API login endpoint (/api/v4/auth/login). Although the Devise :lockable module is enabled, lock and unlock strategies are explicitly disabled, and no rate limiting or throttling is implemented in the Rails code. This flaw permits attackers to perform continuous password guessing without temporary lockout, increasing the risk of account compromise. Successful authentication yields a normal session cookie or a fresh JWT token, facilitating unauthorized access. The API endpoint is particularly vulnerable to automated attacks due to the absence of CSRF token requirements. The issue is patched in version 26.06.08.

Potential Impact

The vulnerability allows attackers to perform unlimited password guessing attempts against valid user accounts without triggering lockout or throttling mechanisms. This increases the risk of successful credential guessing, leading to unauthorized access to user accounts. Compromise via the HTML login flow results in a valid session cookie, while compromise via the API login endpoint yields a fresh JWT token. The API endpoint's lack of CSRF protection makes automated attacks easier. There is no indication of known exploits in the wild at this time.

Mitigation Recommendations

A fixed version (26.06.08) is available that addresses this vulnerability by presumably enabling proper lockout or throttling mechanisms. Users should upgrade to version 26.06.08 or later to remediate this issue. Until upgraded, no official temporary fixes or workarounds are documented. Implementing external rate limiting or monitoring for suspicious login activity may help mitigate risk in the interim.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-03-16T17:35:36.697Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null

Threat ID: 6a5e502f2a4a8d59895edd88

Added to database: 07/20/2026, 16:43:27 UTC

Last enriched: 07/20/2026, 16:57:08 UTC

Last updated: 07/21/2026, 04:38:50 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses