Improper access control in DataEase - #VU140498
Published: July 30, 2026
DataEase
Detailed vulnerability description
The vulnerability allows a remote user to bypass share access restrictions.
The vulnerability exists due to improper access control in ShareTicketManage.validateTicket and the /de2api/share/proxyInfo endpoint when validating share tickets against share UUIDs. A remote user can submit a valid ticket issued for one share against a different share to bypass share access restrictions.
Exploitation requires a valid authenticated session and successful password verification for the target share.