NONE · 0

CVE-2026-50124

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploading payload.zip through the Excel upload API /datasource/upload, creating an H2 da...

Vulnerability Description

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploading payload.zip through the Excel upload API /datasource/upload, creating an H2 datasource that uses the zip: protocol, and executing an SQL dataset path where CalciteProvider.jdbcFetchResultField calls statement.executeQuery(), causing precompiled Java aliases in test.mv.db to execute arbitrary code. This issue is fixed in version 2.10.23.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-50124?

CVE-2026-50124 is a documented vulnerability. DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploading payload.zip through the Excel upload API /datasource/upload, creating an H2 da...

How severe is CVE-2026-50124?

CVSS scoring is not yet available for CVE-2026-50124. Check NVD for updates.

Is there a patch for CVE-2026-50124?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.