CVE-2026-45533: DataEase: Path Traversal Vulnerability
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase export-center deletion can accept path traversal sequences such as ../ in the bulk delete API endpoint and pass attacker-controlled identifiers to ExportCenterManage.delete, allowing recursive deletion of arbitrary server directories through export task cleanup. This issue is fixed in version 2.10.23.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataEaseto a version that resolves this vulnerability.Fixed in 2.10.23
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45533?
CVE-2026-45533 has a risk score of 73, indicating a high severity vulnerability.
What is CVE-2026-45533?
CVE-2026-45533 is a path traversal vulnerability in DataEase prior to version 2.10.23 that allows attackers to manipulate deletion processes.
How do I fix CVE-2026-45533?
To fix CVE-2026-45533, upgrade DataEase to version 2.10.23 or later.
What can an attacker do with CVE-2026-45533?
An attacker can exploit CVE-2026-45533 to execute recursive deletion of arbitrary files through the export-center bulk delete API.
Which versions of DataEase are affected by CVE-2026-45533?
CVE-2026-45533 affects all versions of DataEase prior to 2.10.23.