Junglewise Threat Intelligence

CVE-2026-42463: DataEase SQLBot IDOR and Authorization Bypass in Datasource Endpoints

CVE-2026-42463 · Severity: info · CVSS 8.6 · Published 2026-05-13

Technologies: DataEase SQLBot. Vendors: DataEase.

Executive brief

SQLBot, an AI-powered tool that converts natural language into database queries, contains a security flaw that allows users from one organization to access or modify data belonging to another. By exploiting this vulnerability, a logged-in user could download sensitive database schemas or tamper with the connection settings of other customers' workspaces. This could lead to the exposure of confidential financial or corporate data and disrupt business operations for affected tenants.

Technical details

SQLBot prior to version 1.8.0 is vulnerable to an Insecure Direct Object Reference (IDOR) and authorization bypass in the /api/v1/datasource/exportDsSchema and /api/v1/datasource/uploadDsSchema endpoints. The vulnerability stems from two primary flaws: first, the lack of @require_permissions decorators on core API interfaces, which ensures authentication but fails to verify workspace ownership (oid) for a specific data source (ds_id). Second, a regression caused by upgrading to Pydantic > 2.0 resulted in the truncation of undeclared authorization fields during model instantiation, causing fine-grained permission checks to be bypassed. An authenticated attacker can exploit this to exfiltrate database schemas or modify metadata across different tenant workspaces. The issue is resolved in version 1.8.0.

Affected products

  • DataEase SQLBot < 1.8.0

Timeline

  • 2026-04-30: advisory: GitHub Security Advisory published
  • 2026-05-13: disclosed: NVD publication date

References

Related threats