CVE-2026-46684
CRITICALDataEase: Unauthorized Command Execution Vulnerability
Title source: cnaDescription
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values to TokenUtils.validate(), which checks only token presence and length before userBOByToken(token) uses JWT.decode() without signature verification, allowing forged tokens with chosen uid and oid values to be accepted when licenseValid=true. This issue is fixed in version 2.10.23.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/dataease/dataease/security/advisories/GHSA-gp6v-f7mm-458v
X_Refsource_Misc x_refsource_misc
https://github.com/dataease/dataease/commit/3efda9d29c0df4300d43bb7874638e03060c3e2d
X_Refsource_Misc x_refsource_misc
https://github.com/dataease/dataease/releases/tag/v2.10.23
Scores
CVSS v4
9.5
EPSS
0.0019
EPSS Percentile
9.3%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-347
Status
published
Products (1)
dataease/dataease
< 2.10.23
Published
Jul 15, 2026
Tracked Since
Jul 16, 2026