CVE-2025-46566

CRITICAL

DataEase <2.10.9 - Authenticated RCE

Title source: llm
STIX 2.1

Description

DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.9, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.9.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0059
EPSS Percentile 43.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-284 CWE-923
Status published
Products (1)
dataease/dataease < 2.10.9
Published May 01, 2025
Tracked Since Feb 18, 2026