CVE-2026-82878 PUBLISHED

DataEase before 2.10.26 Missing Object-Level Authorization on Geographic, Linkage and Chart Endpoints

Assigner: VulnCheck
Reserved: 31.08.2026 Published: 31.08.2026 Updated: 31.08.2026

DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging to other users. Attackers can overwrite or delete map geometry, modify dashboard linkages, and retrieve chart metadata and configuration for resources they do not own by supplying arbitrary identifiers in requests.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor dataease
Product dataease
Versions Default: unaffected
  • affected from 0 to 2.10.26 (excl.)
  • Version 2.10.26 is unaffected

Credits

  • Dikai Zou finder

References

Problem Types

  • Missing Authorization CWE