Missing Authorization in DataEase - #VU140502
Published: July 30, 2026
DataEase
Detailed vulnerability description
The vulnerability allows a remote user to modify or delete global map resources.
The vulnerability exists due to improper access control in the geographic information interfaces when handling crafted requests to geographic resource endpoints. A remote user can send requests to persist, delete, or modify map resources to modify or delete global map resources.
The issue affects global geographic information and GeoJSON mappings used by other users and dashboards.