CVE-2026-50530
HIGHDataEase: Token with Overly Broad Privileges in Share Mode: Access to Unshared Datasets
Title source: cnaDescription
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface only validates that sceneId matches the resourceId in the link token and fails to validate whether tableId and field IDs in the request body belong to the shared resource, allowing an attacker with a valid share link token to replace dataset identifiers and retrieve unauthorized data through POST /de2api/chartData/getData. This issue is fixed in version 2.10.24.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/dataease/dataease/security/advisories/GHSA-qcf4-345v-6vg9
X_Refsource_Misc x_refsource_misc
https://github.com/dataease/dataease/commit/c4e85a981e53c95b1ea73757db31e3025efdc410
X_Refsource_Misc x_refsource_misc
https://github.com/dataease/dataease/releases/tag/v2.10.24
Scores
CVSS v4
7.1
EPSS
0.0024
EPSS Percentile
15.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (1)
dataease/dataease
< 2.10.24
Published
Jul 07, 2026
Tracked Since
Jul 08, 2026