A vulnerability was found in Chartbrew 4.9.0. It has been rated as critical. The impacted element is an unknown function. This manipulation of the argument policy_id causes authorization bypass.
This vulnerability is tracked as CVE-2026-40600. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.