NONE · 0

CVE-2026-50530

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface only validates that sceneId matches the resourceId in the link token and fails to v...

Vulnerability Description

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface only validates that sceneId matches the resourceId in the link token and fails to validate whether tableId and field IDs in the request body belong to the shared resource, allowing an attacker with a valid share link token to replace dataset identifiers and retrieve unauthorized data through POST /de2api/chartData/getData. This issue is fixed in version 2.10.24.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-50530?

CVE-2026-50530 is a documented vulnerability. DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface only validates that sceneId matches the resourceId in the link token and fails to v...

How severe is CVE-2026-50530?

CVSS scoring is not yet available for CVE-2026-50530. Check NVD for updates.

Is there a patch for CVE-2026-50530?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.