Missing Authorization in DataEase - #VU140500
Published: July 30, 2026
DataEase
Detailed vulnerability description
The vulnerability allows a remote user to modify or delete other users' share tickets.
The vulnerability exists due to improper access control in the /de2api/ticket/saveTicket and /de2api/ticket/delTicket endpoints when handling ticket update and deletion requests without ownership validation. A remote user can submit a known ticket value to modify ticket bindings and settings or delete the ticket to modify or delete other users' share tickets.
The issue may also allow adjustment of ticket expiry time and configuration parameters.