Missing Authorization in DataEase - #VU140501
Published: July 30, 2026
DataEase
Detailed vulnerability description
The vulnerability allows a remote user to disclose other users' share mappings.
The vulnerability exists due to improper access control in the /de2api/share/queryRelationByUserId/{uid} endpoint when querying share relationships by a supplied user ID without restricting access to the requester's own data or requiring administrator privileges. A remote user can query another user's uid to disclose other users' share mappings.
The exposed data includes mappings between resourceId and share UUID.