CVE-2026-82878

medium

Description

DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging to other users. Attackers can overwrite or delete map geometry, modify dashboard linkages, and retrieve chart metadata and configuration for resources they do not own by supplying arbitrary identifiers in requests.

References

https://www.vulncheck.com/advisories/dataease-before-2.10.26-missing-object-level-authorization-on-geographic-linkage-and-chart-endpoints

https://github.com/dataease/dataease/security/advisories/GHSA-494p-38q6-9gx5

https://github.com/dataease/dataease/releases/tag/v2.10.26

https://github.com/dataease/dataease/commit/5fe46c489876d5decdfcde36d20b1c618d472cbb

https://github.com/dataease/dataease

Details

Source: Mitre, NVD

Published: 2026-08-31

Updated: 2026-08-31

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 6.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Severity: Medium

CVSS v4

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Severity: Medium