SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82878

MEDIUM · CVSS 6.3 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

DataEase versions prior to 2.10.26 lack proper object-level authorization checks on geographic information, dashboard linkages, and chart detail REST endpoints, enabling authenticated users to access and manipulate resources belonging to other users. This vulnerability allows attackers to overwrite or delete map geometry, modify dashboard linkages, and retrieve unauthorized chart metadata and configurations. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized data access and potential data integrity issues.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82878
Severity
MEDIUM
CVSS
6.3
EPSS
0.20%

Original NVD Description

DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging to other users. Attackers can overwrite or delete map geometry, modify dashboard linkages, and retrieve chart metadata and configuration for resources they do not own by supplying arbitrary identifiers in requests.