CVE-2025-32966

CRITICAL

Dataease < 2.10.8 - Authentication Bypass by Spoofing

Title source: rule
STIX 2.1

Description

DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.8.

Scores

CVSS v3 9.8
EPSS 0.1082
EPSS Percentile 93.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-290
Status published
Products (1)
dataease/dataease < 2.10.8
Published Apr 23, 2025
Tracked Since Feb 18, 2026