CVE-2026-53730
dataease
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql endpoint lacks the mandatory @DePermit permission validation annotation, allowing any authenticated user to specify datasourceId=-1, access the built-in engine database, execute arbitrary SQL statements, and read sensitive core data. This issue is fixed in version 2.10.24.
- CVSS
- 8.7
- EPSS
- 0.24% 14.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.08