PT-2026-56248 · Unknown+1 · H2 Database+1

·

CVE-2026-53751

·

Published

2026-07-07

·

Updated

2026-07-15

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions DataEase versions prior to 2.10.24
Description DataEase is an open source data visualization and analysis tool. The H2 database JDBC URL validation logic can be bypassed using special Unicode characters. This occurs because the case-conversion behavior of these characters differs between the validation process in DataEase and the parsing process in H2. This discrepancy allows attackers to smuggle dangerous parameters, such as init, within malicious H2 JDBC connection strings to achieve arbitrary code execution.
Recommendations Update to version 2.10.24.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53751
GHSA-XJHM-R8P8-C2CG

Affected Products

Dataease
H2 Database