PT-2026-56254 · Dataease · Dataease

·

CVE-2026-57172

·

Published

2026-07-07

·

Updated

2026-07-08

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions DataEase versions prior to 2.10.24
Description The ShareSecretManage component uses a hardcoded default share link signature key. An attacker who obtains a passwordless share for a resource and user can use the known key link-pwd-fit2cloud to forge linkToken JSON Web Tokens (JWTs). This allows the attacker to bypass TokenFilter verification and access backend resources as the share creator, even if the original share has been revoked.
Recommendations Update to version 2.10.24.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57172
GHSA-7CPG-F4CJ-7PGM

Affected Products

Dataease