Impact
DataEase prior to version 2.10.26 neglects to enforce object-level authorization on several REST endpoints that expose geographic data, dashboard linkages, and chart configurations. This flaw permits authenticated users to supply arbitrary identifiers in API requests and read, modify, or delete resources that belong to other users. The impact is a breach of confidentiality and integrity for user‑specific data and the ability to tamper with dashboards and maps.
Affected Systems
Products affected are DataEase deployments with versions earlier than 2.10.26. Any installation using the default object‑level authorization controls without the vendor patch is vulnerable. Specific release identifiers can be found at the official DataEase release page for v2.10.26 and the associated GitHub commit that introduced the fix.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating a moderate severity. EPSS data is currently unavailable, and the issue has not been listed in the CISA KEV catalog. Attackers typically would need authentication to interact with the affected endpoints; however, once authenticated, they can freely enumerate other users’ resources by submitting arbitrary identifiers. The lack of authorization checks may lead to unauthorized disclosure, modification, or deletion of sensitive information.
OpenCVE Enrichment