PT-2026-56245 · Dataease · Dataease

·

CVE-2026-50530

·

Published

2026-07-07

·

Updated

2026-07-08

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions DataEase versions prior to 2.10.24
Description A share mode chart data interface fails to validate whether the tableId and field IDs provided in the request body belong to the shared resource. It only verifies that the sceneId matches the resourceId in the link token. This allows an attacker possessing a valid share link token to replace dataset identifiers and retrieve unauthorized data via the 'POST /de2api/chartData/getData' endpoint.
Recommendations Update to version 2.10.24.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50530
GHSA-QCF4-345V-6VG9

Affected Products

Dataease