CVE-2026-32825: CWE-307: Improper Restriction of Excessive Authentication Attempts in datacycle-engine dataCycle-CORE
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application accepts unlimited password guesses against both the browser login flow and the JSON login endpoint. The source code enables Devise's `:lockable` module on the user model but explicitly disables both lock and unlock strategies, and no request throttling or rate-limiting layer was identified in the Rails code. This creates a direct online password-guessing risk: - valid user accounts can be attacked continuously without temporary lockout - the same weakness is reachable through both `/users/sign_in` and `/api/v4/auth/login` - successful guessing yields a normal session cookie in the HTML flow or a fresh JWT in the API flow - the API endpoint is especially attractive for automation because it requires no CSRF token This has been patched in version 26.06.08.
AI Analysis
Technical Summary
CVE-2026-32825 is an improper restriction of excessive authentication attempts vulnerability (CWE-307) in dataCycle-CORE, a data management system. Versions up to 25.07.3 allow unlimited password guesses on both the HTML login flow (/users/sign_in) and the JSON API login endpoint (/api/v4/auth/login). Although the Devise :lockable module is enabled, lock and unlock strategies are explicitly disabled, and no rate limiting or throttling is implemented in the Rails code. This flaw permits attackers to perform continuous password guessing without temporary lockout, increasing the risk of account compromise. Successful authentication yields a normal session cookie or a fresh JWT token, facilitating unauthorized access. The API endpoint is particularly vulnerable to automated attacks due to the absence of CSRF token requirements. The issue is patched in version 26.06.08.
Potential Impact
The vulnerability allows attackers to perform unlimited password guessing attempts against valid user accounts without triggering lockout or throttling mechanisms. This increases the risk of successful credential guessing, leading to unauthorized access to user accounts. Compromise via the HTML login flow results in a valid session cookie, while compromise via the API login endpoint yields a fresh JWT token. The API endpoint's lack of CSRF protection makes automated attacks easier. There is no indication of known exploits in the wild at this time.
Mitigation Recommendations
A fixed version (26.06.08) is available that addresses this vulnerability by presumably enabling proper lockout or throttling mechanisms. Users should upgrade to version 26.06.08 or later to remediate this issue. Until upgraded, no official temporary fixes or workarounds are documented. Implementing external rate limiting or monitoring for suspicious login activity may help mitigate risk in the interim.
CVE-2026-32825: CWE-307: Improper Restriction of Excessive Authentication Attempts in datacycle-engine dataCycle-CORE
Description
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application accepts unlimited password guesses against both the browser login flow and the JSON login endpoint. The source code enables Devise's `:lockable` module on the user model but explicitly disables both lock and unlock strategies, and no request throttling or rate-limiting layer was identified in the Rails code. This creates a direct online password-guessing risk: - valid user accounts can be attacked continuously without temporary lockout - the same weakness is reachable through both `/users/sign_in` and `/api/v4/auth/login` - successful guessing yields a normal session cookie in the HTML flow or a fresh JWT in the API flow - the API endpoint is especially attractive for automation because it requires no CSRF token This has been patched in version 26.06.08.
CVSS v3.1
Score 7.3high
Affected software
pkg:github/datacycle-engine/dataCycle-CORERun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-32825 is an improper restriction of excessive authentication attempts vulnerability (CWE-307) in dataCycle-CORE, a data management system. Versions up to 25.07.3 allow unlimited password guesses on both the HTML login flow (/users/sign_in) and the JSON API login endpoint (/api/v4/auth/login). Although the Devise :lockable module is enabled, lock and unlock strategies are explicitly disabled, and no rate limiting or throttling is implemented in the Rails code. This flaw permits attackers to perform continuous password guessing without temporary lockout, increasing the risk of account compromise. Successful authentication yields a normal session cookie or a fresh JWT token, facilitating unauthorized access. The API endpoint is particularly vulnerable to automated attacks due to the absence of CSRF token requirements. The issue is patched in version 26.06.08.
Potential Impact
The vulnerability allows attackers to perform unlimited password guessing attempts against valid user accounts without triggering lockout or throttling mechanisms. This increases the risk of successful credential guessing, leading to unauthorized access to user accounts. Compromise via the HTML login flow results in a valid session cookie, while compromise via the API login endpoint yields a fresh JWT token. The API endpoint's lack of CSRF protection makes automated attacks easier. There is no indication of known exploits in the wild at this time.
Mitigation Recommendations
A fixed version (26.06.08) is available that addresses this vulnerability by presumably enabling proper lockout or throttling mechanisms. Users should upgrade to version 26.06.08 or later to remediate this issue. Until upgraded, no official temporary fixes or workarounds are documented. Implementing external rate limiting or monitoring for suspicious login activity may help mitigate risk in the interim.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-03-16T17:35:36.697Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5e502f2a4a8d59895edd88
Added to database: 07/20/2026, 16:43:27 UTC
Last enriched: 07/20/2026, 16:57:08 UTC
Last updated: 07/21/2026, 04:38:50 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.