Access Control Vulnerabilities in DataEase Affected by Multiple Issues
CVE-2026-82879
What is CVE-2026-82879?
DataEase before version 2.10.26 exhibits critical access control flaws within its sharing link module, allowing attackers to exploit ticket management. A valid ticket issued for one share can be reused on another, compromising the integrity of shared links. Furthermore, the system's validation processes permit the issuance of LinkTokens without proper ticket verification, undermining the mandatory ticket policy. Additionally, the lack of ownership checks in ticket creation and deletion endpoints enables unauthorized users to manipulate or delete other users' tickets, potentially leading to denial of service. These vulnerabilities also allow authenticated users to enumerate share mappings of others, exacerbating the risk of unauthorized data exposure.
Affected Version(s)
dataease 0 < 2.10.26
dataease 2.10.26
