CVEFinder.io

CVE-2026-33084

⚠️ high
🔍 Scan for this CVE
Summary

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the sort parameter of the /de2api/datasetData/enumValueObj endpoint. The DatasetDataManage service layer directly transfers the user-supplied sort value to the sorting metadata DTO, which is passed to Order2SQLObj where it is incorporated into the SQL ORDER BY clause without any whitelist validation, and then executed via CalciteProvider. An authenticated atta

Description

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the sort parameter of the /de2api/datasetData/enumValueObj endpoint. The DatasetDataManage service layer directly transfers the user-supplied sort value to the sorting metadata DTO, which is passed to Order2SQLObj where it is incorporated into the SQL ORDER BY clause without any whitelist validation, and then executed via CalciteProvider. An authenticated attacker can inject arbitrary SQL commands through the sort parameter, enabling time-based blind SQL injection. This issue has been fixed in version 2.10.21.

CVSS Score
8.8
High
EPSS Score
0.0
Exploit Probability
Published Date
2026-04-16
First Seen: 2026-04-20
📊 Relative Risk Intelligence

This CVE is High Risk - more severe than 81.1% of all 326,604 vulnerabilities in our database.

#61,754
Top 25% most severe
Severity Percentile
🎯 CISA SSVC Assessment Updated: Apr 18, 2026
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2026-04-20
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Vector 4.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)

📦 Affected Products 1

🔗 References 2

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-8724 🔶 medium 4.7 0.0 A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file... 2026-05-17
CVE-2026-33082 ⛔ critical 9.8 0.0 DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerab... 2026-04-16
CVE-2026-33083 ⚠️ high 8.8 0.0 DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... 2026-04-16
CVE-2026-33121 ⚠️ high 8.8 0.0 DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... 2026-04-16
CVE-2026-33122 ⛔ critical 9.8 0.0 DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... 2026-04-16
CVE-2026-33207 ⚠️ high 8.8 0.0 DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... 2026-04-16
These CVEs affect the same products