High severityNVD Advisory· Published Jul 15, 2026· Updated Jul 17, 2026
CVE-2026-45533
CVE-2026-45533
Description
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase export-center deletion can accept path traversal sequences such as ../ in the bulk delete API endpoint and pass attacker-controlled identifiers to ExportCenterManage.delete, allowing recursive deletion of arbitrary server directories through export task cleanup. This issue is fixed in version 2.10.23.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.