CVE-2026-53730: DataEase: Unauthorized Access to Engine Database via previewSql Endpoint
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql endpoint lacks the mandatory @DePermit permission validation annotation, allowing any authenticated user to specify datasourceId=-1, access the built-in engine database, execute arbitrary SQL statements, and read sensitive core data. This issue is fixed in version 2.10.24.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataEaseto a version that resolves this vulnerability.Fixed in 2.10.24
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53730?
The severity of CVE-2026-53730 is classified as high, with a CVSS score of 8.7.
How do I fix CVE-2026-53730?
To mitigate CVE-2026-53730, upgrade DataEase to version 2.10.24 or higher which includes the necessary permission validation.
What does CVE-2026-53730 affect?
CVE-2026-53730 affects the DataEase software, specifically the /de2api/datasetData/previewSql endpoint prior to version 2.10.24.
What kind of vulnerability is CVE-2026-53730?
CVE-2026-53730 is an unauthorized access vulnerability allowing authenticated users to access the built-in engine database.
When was CVE-2026-53730 published?
CVE-2026-53730 was published on July 7, 2026.