Junglewise Threat Intelligence

CVE-2026-55635: DataEase SQL injection in chart quota and Y-axis filters

CVE-2026-55635 · Severity: info · CVSS 8.7 · Published 2026-07-07

Technologies: DataEase. Vendors: DataEase.

Executive brief

DataEase is an open-source tool used by organizations to visualize and analyze business data. A security flaw in how the tool handles chart filters allows authorized users to inject malicious database commands. If exploited, an attacker could bypass security controls to view sensitive information, modify data, or disrupt database operations across connected data sources.

Technical details

An authenticated SQL injection vulnerability exists in DataEase due to improper neutralization of special elements in the Quota2SQLObj.getYWheres() method. Unlike other filter paths in the application, the quota and Y-axis filter path fails to invoke sanitizeSqlLiteral() or validateSqlInjectionRisk(), instead directly concatenating user-provided values from ChartViewFieldFilterDTO into SQL fragments (IN, LIKE, and default comparisons). An attacker with permissions to create or modify chart definitions can provide crafted filter values to execute arbitrary SQL queries against the underlying datasources. This can lead to unauthorized data exfiltration or modification depending on the privileges of the database connection. The issue is resolved in version 2.10.24 by implementing proper sanitization logic.

Affected products

  • DataEase DataEase < 2.10.24

Timeline

  • 2026-06-18: advisory: GitHub Security Advisory published
  • 2026-07-07: disclosed: CVE published to NVD
  • 2026-07-07: patched: Fix released in version 2.10.24

References

Related threats