NONE · 0

CVE-2026-55635

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed attacker-controlled filter values directly into generated SQL in Quota2SQLObj.ge...

Vulnerability Description

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed attacker-controlled filter values directly into generated SQL in Quota2SQLObj.getYWheres() without applying the SQL literal validation and escaping used by other filter paths, allowing an authenticated user who can create or modify chart definitions or submit chart data requests containing quota filters to inject SQL into queries executed against configured datasources. This issue is fixed in version 2.10.24.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-55635?

CVE-2026-55635 is a documented vulnerability. DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed attacker-controlled filter values directly into generated SQL in Quota2SQLObj.ge...

How severe is CVE-2026-55635?

CVSS scoring is not yet available for CVE-2026-55635. Check NVD for updates.

Is there a patch for CVE-2026-55635?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.