CVE-2026-82878: DataEase before 2.10.26 Missing Object-Level Authorization on Geographic, Linkage and Chart Endpoints
DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging to other users. Attackers can overwrite or delete map geometry, modify dashboard linkages, and retrieve chart metadata and configuration for resources they do not own by supplying arbitrary identifiers in requests.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataEaseto a version that resolves this vulnerability.Fixed in 2.10.26
Event History
Frequently Asked Questions
Who is exposed to this issue?
DataEase deployments running versions before 2.10.26 are affected. Exploitation requires an authenticated user account; the issue allows that user to target resources owned by other users.
What does an attacker need to exploit it?
An attacker needs valid authenticated access and the ability to submit requests to the affected geographic information, dashboard linkage, or chart detail REST endpoints. They can supply arbitrary resource identifiers to access objects they do not own.
What could an attacker do?
An attacker could overwrite or delete map geometry, modify dashboard linkages, and retrieve chart metadata and configuration associated with other users' resources.
How can this be remediated?
Upgrade DataEase to version 2.10.26 or later. The vulnerability affects versions before 2.10.26.