CVE-2026-23958: DataEase Vulnerable to Brute-Force Attack on Admin JWT Secret Derived from Password that Enables Full Account Takeover
Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the user’s password as the JWT signing secret. This deterministic secret derivation allows an attacker to brute-force the admin’s password by exploiting unmonitored API endpoints that verify JWT tokens. The vulnerability has been fixed in v2.10.19. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23958?
CVE-2026-23958 has a high severity rating due to its potential for full account takeover through brute-force attacks.
How do I fix CVE-2026-23958?
To fix CVE-2026-23958, upgrade DataEase to version 2.10.19 or later to mitigate the vulnerability.
What does CVE-2026-23958 affect?
CVE-2026-23958 affects versions of DataEase prior to 2.10.19, where the JWT signing secret is derived from the user's password.
What type of attack does CVE-2026-23958 allow?
CVE-2026-23958 allows attackers to perform brute-force attacks against the admin JWT secret, facilitating unauthorized account access.
Is CVE-2026-23958 present in the latest version of DataEase?
No, CVE-2026-23958 is not present in versions of DataEase released after 2.10.19.