Missing Authorization in DataEase - #VU140503
Published: July 30, 2026
DataEase
Detailed vulnerability description
The vulnerability allows a remote user to modify or delete linkage configurations belonging to other users' dashboards.
The vulnerability exists due to improper access control in the linkage write interfaces when processing requests that supply dashboard and view identifiers. A remote user can send a specially crafted request using another user's dashboard identifiers to modify or delete linkage configurations belonging to other users' dashboards.
Exploitation requires knowledge of another user's dashboard ID.