NONE · 0

CVE-2026-46684

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values to TokenUtils.validate(), wh...

Vulnerability Description

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values to TokenUtils.validate(), which checks only token presence and length before userBOByToken(token) uses JWT.decode() without signature verification, allowing forged tokens with chosen uid and oid values to be accepted when licenseValid=true. This issue is fixed in version 2.10.23.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-46684?

CVE-2026-46684 is a documented vulnerability. DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values to TokenUtils.validate(), wh...

How severe is CVE-2026-46684?

CVSS scoring is not yet available for CVE-2026-46684. Check NVD for updates.

Is there a patch for CVE-2026-46684?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.