Improper Access Control in SQLBot Dashboard by DataEase
CVE-2026-93660
7.1HIGH
What is CVE-2026-93660?
SQLBot versions up to 1.10.1 exhibit a significant flaw in dashboard ownership verification. This vulnerability allows authenticated users within a workspace to manipulate the private dashboards of other users. Specifically, attackers can exploit the update_resource and update_canvas endpoints by submitting arbitrary dashboard IDs, enabling them to rename dashboards and overwrite critical data including component configurations, canvas styles, and view information. This could lead to unauthorized access and disruption of services within collaborative environments.
Affected Version(s)
SQLBot 0 <= 1.10.1
