SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-75978

MEDIUM · CVSS 6.3 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects the xianrendzw EasyReport application up to version 2.0.17.0522_Beta, specifically within the DataSourceController.add function in DataSourceController.java, where improper handling of the queryerClass argument can lead to permission issues. This flaw allows for remote exploitation, potentially compromising the integrity and security of the application. Organizations using this software should prioritize patching or mitigating this vulnerability, as it has been publicly disclosed and could be actively exploited.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75978
Severity
MEDIUM
CVSS
6.3
EPSS
0.28%
Java

Original NVD Description

A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController.add of the file DataSourceController.java of the component QueryerFactory. Such manipulation of the argument queryerClass leads to permission issues. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.