Missing Authorization in DataEase - #VU140501

 

Missing Authorization in DataEase - #VU140501

Published: July 30, 2026


Vulnerability identifier: #VU140501
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
DataEase

Detailed vulnerability description

The vulnerability allows a remote user to disclose other users' share mappings.

The vulnerability exists due to improper access control in the /de2api/share/queryRelationByUserId/{uid} endpoint when querying share relationships by a supplied user ID without restricting access to the requester's own data or requiring administrator privileges. A remote user can query another user's uid to disclose other users' share mappings.

The exposed data includes mappings between resourceId and share UUID.


Remediation

Install security update from vendor's website.

Sources