CVE-2026-50530: DataEase: Token with Overly Broad Privileges in Share Mode: Access to Unshared Datasets
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface only validates that sceneId matches the resourceId in the link token and fails to validate whether tableId and field IDs in the request body belong to the shared resource, allowing an attacker with a valid share link token to replace dataset identifiers and retrieve unauthorized data through POST /de2api/chartData/getData. This issue is fixed in version 2.10.24.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataEaseto a version that resolves this vulnerability.Fixed in 2.10.24
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50530?
The severity of CVE-2026-50530 is classified as high with a score of 7.1.
How do I fix CVE-2026-50530?
To fix CVE-2026-50530, update DataEase to version 2.10.24 or later.
What is the risk associated with CVE-2026-50530?
CVE-2026-50530 carries a risk score of 40.
What type of vulnerability is CVE-2026-50530?
CVE-2026-50530 is a vulnerability related to overly broad privileges in Share Mode access.
What can attackers exploit in CVE-2026-50530?
Attackers can exploit CVE-2026-50530 to gain unauthorized access to unshared datasets due to inadequate validation of IDs.