High severityNVD Advisory· Published Jul 7, 2026· Updated Jul 8, 2026
CVE-2026-50529
CVE-2026-50529
Description
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share interface generates and returns X-DE-LINK-TOKEN before validating the share password or ticket, allowing unauthenticated attackers who know a protected share UUID to obtain a valid link token for subsequent share-related API calls even with missing or invalid credentials. This issue is fixed in version 2.10.24.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.