CVE-2026-82879 PUBLISHED

DataEase before 2.10.26 Access Control Bypass via Share Tickets

Assigner: VulnCheck
Reserved: 31.08.2026 Published: 31.08.2026 Updated: 31.08.2026

DataEase before 2.10.26 contains multiple access control defects in the sharing link module. Tickets are not bound to the target share UUID, so a valid ticket issued for one share can be reused against another (ShareTicketManage.validateTicket / POST /de2api/share/proxyInfo). The POST /de2api/share/validate endpoint issues a LinkToken after password verification without requiring a ticket, bypassing the 'ticket mandatory' policy. Additionally, the ticket create and delete endpoints (POST /de2api/ticket/saveTicket, POST /de2api/ticket/delTicket) lack share-ownership checks, allowing an authenticated user who knows another user's ticket to modify, rebind, or delete it (denial of service), and GET /de2api/share/queryRelationByUserId/{uid} allows authenticated users to enumerate other users' share mappings.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor dataease
Product dataease
Versions Default: unaffected
  • affected from 0 to 2.10.26 (excl.)
  • Version 2.10.26 is unaffected

Credits

  • Dikai Zou finder

References

Problem Types

  • Incorrect Authorization CWE