CVE-2026-53751: DataEase: H2 JDBC URL Filter Bypass Leads to Remote Code Execution (RCE)
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation logic can be bypassed with special Unicode characters whose case-conversion behavior differs between DataEase validation and H2 parsing, allowing attackers to smuggle dangerous parameters such as init in malicious H2 JDBC connection strings and achieve arbitrary code execution. This issue is fixed in version 2.10.24.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataEaseto a version that resolves this vulnerability.Fixed in 2.10.24
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53751?
The severity of CVE-2026-53751 is high, with a CVSS score of 8.7.
How do I fix CVE-2026-53751?
To fix CVE-2026-53751, upgrade DataEase to version 2.10.24 or later.
What type of vulnerability is CVE-2026-53751?
CVE-2026-53751 is classified as a code injection vulnerability.
What risk does CVE-2026-53751 pose?
CVE-2026-53751 has a risk score of 79, indicating a significant threat level.
What systems are affected by CVE-2026-53751?
CVE-2026-53751 affects DataEase versions prior to 2.10.24.