---
id: CVE-2026-82878
title: >-
  DataEase versions before 2.10.26 omit object-level authorization checks on
  geographic information, dashboard linkage, and chart detail REST endpoints,
  allowing authenticated users to access resources belonging to other users
summary: >-
  DataEase versions before 2.10.26 omit object-level authorization checks on
  geographic information, dashboard linkage, and chart detail REST endpoints,
  allowing authenticated users to access resources belonging to other users.
  Attackers c…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-862
published: '2026-08-31'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:18:59.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82878'
references:
  - url: 'https://github.com/dataease/dataease'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/dataease/dataease/commit/5fe46c489876d5decdfcde36d20b1c618d472cbb
    label: disclosure@vulncheck.com
  - url: 'https://github.com/dataease/dataease/releases/tag/v2.10.26'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/dataease/dataease/security/advisories/GHSA-494p-38q6-9gx5
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/dataease-before-2.10.26-missing-object-level-authorization-on-geographic-linkage-and-chart-endpoints
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00344
epssPercentile: 0.25188
ingestedAt: '2026-09-08T21:11:12.288Z'
---

## Overview

DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging to other users. Attackers can overwrite or delete map geometry, modify dashboard linkages, and retrieve chart metadata and configuration for resources they do not own by supplying arbitrary identifiers in requests.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
