Description
DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging to other users. Attackers can overwrite or delete map geometry, modify dashboard linkages, and retrieve chart metadata and configuration for resources they do not own by supplying arbitrary identifiers in requests.
Published: 2026-08-31
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

DataEase prior to version 2.10.26 neglects to enforce object-level authorization on several REST endpoints that expose geographic data, dashboard linkages, and chart configurations. This flaw permits authenticated users to supply arbitrary identifiers in API requests and read, modify, or delete resources that belong to other users. The impact is a breach of confidentiality and integrity for user‑specific data and the ability to tamper with dashboards and maps.

Affected Systems

Products affected are DataEase deployments with versions earlier than 2.10.26. Any installation using the default object‑level authorization controls without the vendor patch is vulnerable. Specific release identifiers can be found at the official DataEase release page for v2.10.26 and the associated GitHub commit that introduced the fix.

Risk and Exploitability

The vulnerability carries a CVSS score of 5.3, indicating a moderate severity. EPSS data is currently unavailable, and the issue has not been listed in the CISA KEV catalog. Attackers typically would need authentication to interact with the affected endpoints; however, once authenticated, they can freely enumerate other users’ resources by submitting arbitrary identifiers. The lack of authorization checks may lead to unauthorized disclosure, modification, or deletion of sensitive information.

Generated by OpenCVE AI on August 31, 2026 at 12:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade DataEase to version 2.10.26 or later to apply the vendor‑supplied fix for object‑level authorization checks.
  • Ensure that all deployed instances enforce least‑privilege policies and delete any users or service accounts that are no longer needed or have excessive permissions.
  • Monitor API logs for requests that reference identifiers not owned by the authenticated user and set alerts on anomalous access patterns.

Generated by OpenCVE AI on August 31, 2026 at 12:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Description DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging to other users. Attackers can overwrite or delete map geometry, modify dashboard linkages, and retrieve chart metadata and configuration for resources they do not own by supplying arbitrary identifiers in requests.
Title DataEase before 2.10.26 Missing Object-Level Authorization on Geographic, Linkage and Chart Endpoints
First Time appeared Dataease
Dataease dataease
Weaknesses CWE-862
CPEs cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*
Vendors & Products Dataease
Dataease dataease
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Dataease Dataease
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-31T10:51:04.541Z

Reserved: 2026-08-31T08:38:43.268Z

Link: CVE-2026-82878

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T11:16:41.467

Modified: 2026-08-31T11:16:41.467

Link: CVE-2026-82878

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T12:30:05Z

Weaknesses