Description
A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController.add of the file DataSourceController.java of the component QueryerFactory. Such manipulation of the argument queryerClass leads to permission issues. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-08-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in EasyReport's DataSourceController.add function. By manipulating the queryerClass argument, a remote attacker can bypass intended access controls, potentially executing arbitrary queries or achieving broader system privileges. This flaw stems from improper handling of input, allowing unauthorized operations that contravene expected permissions.

Affected Systems

The flaw affects xianrendzw EasyReport versions up to 2.0.17.0522_Beta. The component impacted is QueryerFactory's DataSourceController.java. Users running any unpatched release of this product are susceptible.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate risk, and the attack vector is remote, relying on crafted input to the add endpoint. No public exploitation has been confirmed, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the exploit has been disclosed and could be used by malicious actors when the application is exposed to network traffic.

Generated by OpenCVE AI on August 19, 2026 at 06:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade EasyReport to a release newer than 2.0.17.0522_Beta or apply any vendor-provided patch that addresses the DataSourceController.add input validation.
  • If a patch is unavailable, restrict remote access to the DataSourceController.add endpoint or enforce role‑based access control to limit who can call it.
  • Implement input validation on the queryerClass parameter to accept only pre‑defined, allowed values and reject any unexpected payloads.

Generated by OpenCVE AI on August 19, 2026 at 06:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController.add of the file DataSourceController.java of the component QueryerFactory. Such manipulation of the argument queryerClass leads to permission issues. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title xianrendzw EasyReport QueryerFactory DataSourceController.java DataSourceController.add permission
First Time appeared Xianrendzw
Xianrendzw easyreport
Weaknesses CWE-266
CWE-275
CPEs cpe:2.3:a:xianrendzw:easyreport:*:*:*:*:*:*:*:*
Vendors & Products Xianrendzw
Xianrendzw easyreport
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Xianrendzw Easyreport
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-21T19:24:51.463Z

Reserved: 2026-08-18T18:15:34.123Z

Link: CVE-2026-75978

cve-icon Vulnrichment

Updated: 2026-08-21T19:24:44.988Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T00:16:28.810

Modified: 2026-08-21T20:16:43.060

Link: CVE-2026-75978

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T11:45:04Z

Weaknesses