Missing Authentication for Critical Function in DataEase - #VU140499
Published: July 30, 2026
DataEase
Detailed vulnerability description
The vulnerability allows a remote user to bypass mandatory ticket requirements for shared resources.
The vulnerability exists due to improper access control in the /de2api/share/validate endpoint when verifying the share UUID and password without requiring a ticket. A remote user can submit a share UUID and password without a ticket to bypass mandatory ticket requirements for shared resources.
This issue affects shares configured with ticketRequire=true.