CVE-2026-82878

DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging to other users. Attackers can overwrite or delete map geometry, modify dashboard linkages, and retrieve chart metadata and configuration for resources they do not own by supplying arbitrary identifiers in requests.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-31 11:16

Updated : 2026-09-08 20:18


NVD link : CVE-2026-82878

Mitre link : CVE-2026-82878

CVE.ORG link : CVE-2026-82878


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization