CVE-2026-32140Disclosure(dataease / dataease)

LOWCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for dataease dataease systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to load an attacker-controlled configuration file. This configuration file can inject dangerous JDBC properties, leading to remote code execution. The Redshift JDBC driver execution flow reaches a method named getJdbcIniFile. The getJdbcIniFile method implements an aggressive automatic configuration file discovery mechanism. If not explicitly restricted, it searches for a file named rsjdbc.ini. In a JDBC URL context, users can explicitly specify the configuration file via URL parameters, which allows arbitrary files on the server to be loaded as JDBC configuration files. Within the Redshift JDBC driver properties, the parameter IniFile is explicitly supported and used to load an external configuration file. This vulnerability is fixed in 2.10.20.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dataease

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-12); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
dataease

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-12: 2Mentions · 2026-03-13: 1Active Exploitation · 2026-03-12: 1Technical Details · 2026-03-12: 2Technical Details · 2026-03-13: 103-1203-13
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-122
Disclosure2
2026-03-131
General1
Full discourse3 posts
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-32140 - High Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to load an attacker-controlled confi... https://www.thehackerwire.com/vulnerability/CVE-2026-32140/ https://t.co/aplkqL1dRq

    Post summary

    The post reports on CVE‑2026‑32140, noting that manipulation of the IniFile parameter can lead to loading attacker‑controlled JDBC driver configurations, but it provides no evidence of exploitation, PoC, or patches.

    0000041
    134 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32140 Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to load an … https://www.cve.org/CVERecord?id=CVE-2026-32140

    Post summary

    The text announces CVE‑2026‑32140 for Dataease, giving a brief technical description of how controlling a parameter can lead to an exploitation vector, but does not provide a PoC, exploit code, active exploitation evidence, or patch information.

    00000145
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32140: Dataease: Redshift JDBC RCE Bypa... JDBC URL injection through IniFile param bypasses Redshift driver security - attackers drop malicious configs for insta... https://zerodaysignal.com/vulnerability/CVE-2026-32140 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-32140, a JDBC URL injection flaw in Dataease that allows attackers to bypass Redshift driver security and achieve remote code execution, with evidence of active exploitation but no mitigation or exploit code provided.

    0000052
    143 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdataeasedataease---

Explore more