CVE-2026-82878
DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST
CVSS
6.3
Medio
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 31 ago 2026 · Última mod.: 31 ago 2026 · CWE-862
Sin historial EPSS suficiente todavía.
DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging to other users. Attackers can overwrite or delete map geometry, modify dashboard linkages, and retrieve chart metadata and configuration for resources they do not own by supplying arbitrary identifiers in requests.
- github.comhttps://github.com/dataease/dataease
- github.comhttps://github.com/dataease/dataease/commit/5fe46c489876d5decdfcde36d20b1c618d472cbb
- github.comhttps://github.com/dataease/dataease/releases/tag/v2.10.26
- github.comhttps://github.com/dataease/dataease/security/advisories/GHSA-494p-38q6-9gx5
- www.vulncheck.comhttps://www.vulncheck.com/advisories/dataease-before-2.10.26-missing-object-level-authorization-on-geographic-linkage-and-chart-endpoints
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-828717.7 ALT—
——0ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data. Attackers can supply arbitrary organization IDs in URL parameters to list tables, retrieve column definitions, and execute join queries to read actual stored data from victim organizations.3hCVE-2026-826605.4 MED—
——0Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.3hCVE-2026-825444.3 MED—
——0A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password Reset. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely. This patch is called 3c6ce4b7f3eeafeb35318c6c4e82b1a3fd28b314. It is advisable to implement a patch to correct this issue.22hCVE-2026-826334.3 MED—
——0Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of other users. Attackers can call GET /users/{id}/groups with arbitrary user identifiers to access group names, entity associations, and private notes across tenant boundaries.23hCVE-2026-824758.1 ALT16.9%
——5iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions.2dCVE-2026-813464.3 MED4.7%
——1The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.1d