Impact
DataEase versions prior to 2.10.26 contain an access control defect in the sharing link module where tickets are not bound to the intended share UUID. A valid ticket issued for one share can be replayed against another, allowing an attacker to obtain a LinkToken and effectively bypass the intended security boundary. The flaw also lets a user who knows another’s ticket modify, rebind, or delete it, and enables enumeration of share relations. The weakness is classified as CWE‑863, reflecting a flaw in authorization checks.
Affected Systems
All installations of DataEase version 2.10.25 and earlier. The vulnerability affects the share ticket endpoints provided by the dataease:dataease product. Users running the operating warehouse or dashboard services without the 2.10.26 patch are susceptible. No other vendors or product lines are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity due to limited impact beyond the share privileges. EPSS data is not available, and the issue is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not been observed yet. Exploitation requires authentication to the target instance, meaning an attacker must compromise or obtain valid user credentials or possess a legitimate ticket from another user. Once authenticated, the attacker can reuse a ticket against a different share, elevate access rights, or cause denial of service by deleting other users’ tickets. The absence of strict ownership checks opens the path for this misuse.
OpenCVE Enrichment