Authorization bypass through user-controlled key in DataEase - #VU140504
Published: July 30, 2026
DataEase
Detailed vulnerability description
The vulnerability allows a remote user to disclose chart metadata and partial calculation results.
The vulnerability exists due to improper access control in the chart ID-based access endpoints when processing requests that reference chart, dataset, or field identifiers. A remote user can send a specially crafted request with a known chart ID to disclose chart metadata and partial calculation results.
In multi-tenant or multi-project deployments, this can result in cross-user or cross-project information leakage.