Description
SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary dashboard IDs to rename dashboards and overwrite component data, canvas styles, and view information belonging to other workspace members.
Published: 2026-09-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privileged Data Modification
Action: Patch Immediately
AI Analysis

Impact

A flaw in the update_resource and update_canvas endpoints of SQLBot up to version 1.10.1 allows an authenticated workspace member to supply any dashboard identifier and perform modifications on dashboards that the user does not own. The application fails to verify ownership before applying changes, permitting attackers to rename dashboards and overwrite component data, canvas styles, and view information that belong to other workspace members. This results in integrity violations and potential exposure of private configuration details, and could facilitate escalation within the workspace if sensitive metadata is altered.

Affected Systems

The vulnerability applies to DataEase’s SQLBot product, versions 1.10.1 and earlier. No additional vendor or product versions are listed in the advisory.

Risk and Exploitability

The CVSS score of 7.1 indicates a high level of severity. The EPSS score is less than 1%, indicating a low probability of exploitation, and the lack of a KEV listing suggests no known active attacks yet. Attackers must be authenticated members of a workspace to gain access to the endpoints, but because ownership checks are omitted, any legitimate session within that workspace can be abused to tamper with other users’ dashboards.

Generated by OpenCVE AI on September 19, 2026 at 19:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest SQLBot release that fixes the ownership validation in dashboard update endpoints.
  • Restrict or disable the update_resource and update_canvas APIs for non-owners until a patch is available.
  • Re‑evaluate workspace permission settings to ensure that only owners can modify dashboards.

Generated by OpenCVE AI on September 19, 2026 at 19:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Dataease
Dataease sqlbot
Vendors & Products Dataease
Dataease sqlbot

Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary dashboard IDs to rename dashboards and overwrite component data, canvas styles, and view information belonging to other workspace members.
Title SQLBot through 1.10.1 Improper Access Control via Dashboard Update
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-22T14:36:08.735Z

Reserved: 2026-09-18T13:30:26.643Z

Link: CVE-2026-93660

cve-icon Vulnrichment

Updated: 2026-09-22T14:36:00.791Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T15:17:22.667

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-93660

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:15:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key