HIGH
DataEase Vulnerable to Brute-Force Attack on Admin JWT Secret Derived from Password that Enables Full Account Takeover
Published Jan 22, 2026
8.8
HIGHCVSS 4.0
EPSS 0.53%
Description
Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the user’s password as the JWT signing secret. This deterministic secret derivation allows an attacker to brute-force the admin’s password by exploiting unmonitored API endpoints that verify JWT tokens. The vulnerability has been fixed in v2.10.19. No known workarounds are available.
Affected products
-
- Version < 2.10.19StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-4206 Advisory
- https://github.com/dataease/dataease/security/advisories/GHSA-5wvm-4m4q-rh7j x_refsource_CONFIRMExploitVendor Advisory
- https://www.ox.security/blog/blog-dataease-cve-2026-23958-admin-takeover/ ExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-4206 | Advisory | |
| https://github.com/dataease/dataease/security/advisories/GHSA-5wvm-4m4q-rh7j | x_refsource_CONFIRMExploitVendor Advisory | |
| https://www.ox.security/blog/blog-dataease-cve-2026-23958-admin-takeover/ | ExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jan 22, 2026
Updated Jan 26, 2026
Reserved Jan 19, 2026
Link CVE-2026-23958
CISA Vulnrichment
Updated Jan 22, 2026
ENISA EUVD
EUVD-2026-4206 Assigner GitHub_M
Published Jan 22, 2026
Updated Jan 26, 2026
Exploited since n/a
Link EUVD-2026-4206