Access Control Vulnerabilities in DataEase Affected by Multiple Issues
CVE-2026-82879

5.3MEDIUM

Key Information:

Vendor

Dataease

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82879?

DataEase before version 2.10.26 exhibits critical access control flaws within its sharing link module, allowing attackers to exploit ticket management. A valid ticket issued for one share can be reused on another, compromising the integrity of shared links. Furthermore, the system's validation processes permit the issuance of LinkTokens without proper ticket verification, undermining the mandatory ticket policy. Additionally, the lack of ownership checks in ticket creation and deletion endpoints enables unauthorized users to manipulate or delete other users' tickets, potentially leading to denial of service. These vulnerabilities also allow authenticated users to enumerate share mappings of others, exacerbating the risk of unauthorized data exposure.

Affected Version(s)

dataease 0 < 2.10.26

dataease 2.10.26

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dikai Zou
.