VYPR
Unrated severityNVD Advisory· Published Jul 7, 2026· Updated Jul 8, 2026

DataEase H2 RCE via Zip Protocol & File Dropper Fix bypass

CVE-2026-55633

Description

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and file dropper fix allows an authenticated attacker to upload a zip archive disguised with a .ttf extension through FontManage.saveFile and then exploit it through the zip protocol to achieve remote code execution. This issue is fixed in version 2.10.24.

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.