CVE-2026-50030

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL preview exposes DatasetDataApi.previewSql/previewSqlCheck through /de2api/datasetData/previewSql, accepts PreviewSqlDTO.sql, PreviewSqlDTO.datasourceId, and PreviewSqlDTO.isCross, then DatasetDataManage.previewSql stores decoded SQL in datasourceRequest.query and CalciteProvider.fetchResultField executes it with prepareStatement(...).executeQuery(), allowing arbitrary readable datasource tables to be queried and returned in preview responses. This issue is fixed in version 2.10.23.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Jul 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 20:17

Updated : 2026-07-18 02:17


NVD link : CVE-2026-50030

Mitre link : CVE-2026-50030

CVE.ORG link : CVE-2026-50030


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')