Authorization bypass through user-controlled key in DataEase - CVE-2026-53730
Published: June 18, 2026
DataEase
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the /de2api/datasetData/previewSql endpoint when handling crafted API requests with datasourceId=-1. A remote user can send a specially crafted request to disclose sensitive information.
The issue allows execution of arbitrary SQL statements against the built-in engine database.