DataEase Open Source Tool Affected by Locale Handling Issues
CVE-2026-32939

7.7HIGH

Key Information:

Vendor

Dataease

Status
Vendor
CVE Published:
20 March 2026

What is CVE-2026-32939?

DataEase, an open-source data visualization analysis tool, has been identified to have a locale handling issue that affects its JDBC URL validation. Prior to version 2.10.20, the application relied on the JVM's default runtime locale when processing security checks, leading to inconsistencies with how it interprets JDBC URLs compared to the H2 JDBC engine. This discrepancy arises particularly in Turkish locale settings, where Java converts 'i' into 'İ', potentially allowing a malicious user to bypass security filters. Attackers could exploit this flaw to smuggle harmful JDBC parameters, compromising the integrity of DataEase's security mechanisms. The issue has been confirmed in real-world deployments, highlighting the need for users to upgrade to the fixed version 2.10.20 to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

dataease < 2.10.20

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.