Executive brief
DataEase is an open-source tool used for data visualization and business intelligence. A security flaw in the way it handles shared links allows unauthorized individuals to bypass password protections on shared dashboards or reports. By exploiting this, an attacker who knows the unique ID of a shared resource can access sensitive data without providing the required password or security ticket.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the DataEase '/de2api/share/proxyInfo' endpoint. The root cause is that the 'XpackShareManage.proxyInfo()' method generates and returns an 'X-DE-LINK-TOKEN' in the HTTP response header before performing validation of the share password or ticket. An unauthenticated remote attacker with knowledge of a protected share UUID can obtain this valid link token despite providing invalid or empty credentials. This token can then be used to authenticate subsequent API calls, such as 'chartData/getData', effectively bypassing intended access controls. The issue is resolved in version 2.10.24.
Affected products
- DataEase DataEase < 2.10.24
Timeline
- 2026-06-18: patched: Fixed in version 2.10.24
- 2026-06-18: advisory: GitHub Security Advisory GHSA-7287-qqj9-phr6 published
- 2026-07-07: disclosed: CVE-2026-50529 published to NVD