AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-57172

HIGH · CVSS 8.3 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

The vulnerability in DataEase stems from a hardcoded default share link signature key in the ShareSecretManage component, which allows attackers to forge linkToken JWTs and bypass TokenFilter verification. This could enable unauthorized access to backend resources as if they were the original share creator, even after the share has been revoked. Organizations using versions prior to 2.10.24 should prioritize updating to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-57172
Severity
HIGH
CVSS
8.3
EPSS
0.29%

Original NVD Description

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded default share link signature key, allowing an attacker who can obtain a passwordless share for a resource and user to use the known key link-pwd-fit2cloud to forge linkToken JWTs, bypass TokenFilter verification, and access backend resources as the share creator even if the original share has been revoked. This issue is fixed in version 2.10.24.