Improper Access Control in SQLBot Dashboard by DataEase
CVE-2026-93660

7.1HIGH

Key Information:

Vendor

Dataease

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-93660?

SQLBot versions up to 1.10.1 exhibit a significant flaw in dashboard ownership verification. This vulnerability allows authenticated users within a workspace to manipulate the private dashboards of other users. Specifically, attackers can exploit the update_resource and update_canvas endpoints by submitting arbitrary dashboard IDs, enabling them to rename dashboards and overwrite critical data including component configurations, canvas styles, and view information. This could lead to unauthorized access and disruption of services within collaborative environments.

Affected Version(s)

SQLBot 0 <= 1.10.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.