Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Tes0T5

#31979of 56,329
8.7Total CVSS
Vulnerabilities · 1
PT-2026-56246
8.7
2026-07-07
Dataease · Dataease · CVE-2026-53729
**Name of the Vulnerable Software and Affected Versions** DataEase versions prior to 2.10.24 **Description** Authenticated users can perform unauthorized actions on export tasks belonging to other users by manipulating the task ID parameter. Affected actions include downloading files via the '/exportCenter/download/{id}' endpoint, deleting tasks via '/exportCenter/delete', retrying tasks via '/exportCenter/retry/{id}', and generating download links via '/exportCenter/generateDownloadUri/{id}'. Additionally, the '/exportCenter/download/{id}' endpoint is whitelisted from authentication, which allows unauthenticated access to exported files. **Recommendations** Update to version 2.10.24.