Improper access control in DataEase - CVE-2026-50530
Published: June 18, 2026
DataEase
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the POST /de2api/chartData/getData endpoint when handling share-mode chart data requests. A remote user can send a specially crafted request with a valid share link token while tampering with tableId and field identifiers to disclose sensitive information.
Exploitation requires a valid share link token and keeping the legitimate sceneId unchanged while referencing identifiers from an unshared dataset.