CVE-2026-50529: DataEase: Link Token Leakage Prior to Share Password/Ticket Validation
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share interface generates and returns X-DE-LINK-TOKEN before validating the share password or ticket, allowing unauthenticated attackers who know a protected share UUID to obtain a valid link token for subsequent share-related API calls even with missing or invalid credentials. This issue is fixed in version 2.10.24.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataEaseto a version that resolves this vulnerability.Fixed in 2.10.24
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50529?
CVE-2026-50529 has a high severity rating of 8.7 according to the CVSS.
How do I fix CVE-2026-50529?
To mitigate CVE-2026-50529, upgrade DataEase to version 2.10.24 or later.
What risk does CVE-2026-50529 pose?
CVE-2026-50529 poses a risk of token leakage, allowing unauthenticated attackers to access protected share data.
What is the impact of CVE-2026-50529?
The impact of CVE-2026-50529 is the potential unauthorized access to valid link tokens, compromising sensitive data.
Is authentication required to exploit CVE-2026-50529?
No, CVE-2026-50529 can be exploited by unauthenticated attackers who know the share UUID.