Missing Authorization in DataEase - #VU140500

 

Missing Authorization in DataEase - #VU140500

Published: July 30, 2026


Vulnerability identifier: #VU140500
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
DataEase

Detailed vulnerability description

The vulnerability allows a remote user to modify or delete other users' share tickets.

The vulnerability exists due to improper access control in the /de2api/ticket/saveTicket and /de2api/ticket/delTicket endpoints when handling ticket update and deletion requests without ownership validation. A remote user can submit a known ticket value to modify ticket bindings and settings or delete the ticket to modify or delete other users' share tickets.

The issue may also allow adjustment of ticket expiry time and configuration parameters.


Remediation

Install security update from vendor's website.

Sources