Missing Authorization in DataEase - #VU140502

 

Missing Authorization in DataEase - #VU140502

Published: July 30, 2026


Vulnerability identifier: #VU140502
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
DataEase

Detailed vulnerability description

The vulnerability allows a remote user to modify or delete global map resources.

The vulnerability exists due to improper access control in the geographic information interfaces when handling crafted requests to geographic resource endpoints. A remote user can send requests to persist, delete, or modify map resources to modify or delete global map resources.

The issue affects global geographic information and GeoJSON mappings used by other users and dashboards.


Remediation

Install security update from vendor's website.

Sources