CVE-2026-82878
DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging to other users.
Does this matter?
Lower severity and a low EPSS score (0.20%). Track it; it rarely justifies an emergency change on its own.
Description
DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging to other users. Attackers can overwrite or delete map geometry, modify dashboard linkages, and retrieve chart metadata and configuration for resources they do not own by supplying arbitrary identifiers in requests.
- CVSS 4.0
- 5.3 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.20% probability · 10th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Source
- disclosure@vulncheck.com
References
- https://github.com/dataease/dataease
- https://github.com/dataease/dataease/commit/5fe46c489876d5decdfcde36d20b1c618d472cbb
- https://github.com/dataease/dataease/releases/tag/v2.10.26
- https://github.com/dataease/dataease/security/advisories/GHSA-494p-38q6-9gx5
- https://www.vulncheck.com/advisories/dataease-before-2.10.26-missing-object-level-authorization-on-geographic-linkage-and-chart-endpoints
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.