CVE-2026-23958PoC(dataease / dataease)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the user’s password as the JWT signing secret. This deterministic secret derivation allows an attacker to brute-force the admin’s password by exploiting unmonitored API endpoints that verify JWT tokens. The vulnerability has been fixed in v2.10.19. No known workarounds are available.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-522

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dataease

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Exploit: 1 classified signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-06-08)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
dataease

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-25: 1Mentions · 2026-06-08: 2PoC Mentioned / Linked · 2026-05-25: 1Technical Details · 2026-05-25: 1Technical Details · 2026-06-08: 205-2506-08
Signal classification3 categories
PoC
133.3%
Exploit
133.3%
General
133.3%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-05-251
PoC1
2026-06-082
Exploit1General1
Full discourse3 posts
  • Moshe Siman Tov Bustan@MosheTov
    PoC

    4-Vulnerability Exploit Chain in DataEase My team found a 4-vulnerability exploit chain allowing unauthenticated RCE on DataEase. Combined with a previously published vulnerability (CVE-2026-23958) - these new vulns complete the attack chain, bypassing JDBC, SQL Injection and a Quartz scheduler injection that runs periodically and executes a crafted payload on the machine. We have also a video showing the exploit POC in action :) Read the full blog: http://ox.security/blog/from-auth-bypass-to-rce-a-4-vulnerability-exploit-chain-in-dataease

    Post summary

    The post announces a 4‑vulnerability exploitation chain against DataEase, provides a video proof‑of‑concept, and outlines technical details of the attack, but does not include a functional exploit tool, active exploitation claims, or remediation information.

    0802062.9K
    1.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Exploit

    CVE-2026-23958: 4-Vulnerability Exploit Chain in DataEase My team found a 4-vulnerability exploit chain allowing unauthenticated RCE on DataEase. Combined with a previously published vulnerability (CVE-2026-23958) - these new vulns complete the attack chain, bypassing…

    Post summary

    Authors report discovering a four‑vulnerability chain that enables unauthenticated remote code execution on DataEase, building on the previously published CVE‑2026‑23958.

    1000039
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Combined with a previously published vulnerability (CVE-2026-23958) - these new vulns complete the attack chain, bypassing JDBC, SQL Injection and a Source: X search for RCE 2026 exploit Posted: 2026-05-25T11:49:49.000Z Likes: 19

    Post summary

    The message notes that additional vulnerabilities, together with CVE-2026-23958, provide a complete attack chain involving JDBC bypass and SQL injection, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    1000046
    258 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdataeasedataease---

Explore more