Sploitus

CVE-2026-50124

No indexed exploits for CVE-2026-50124 yet

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploading payload.zip through the Excel upload API /datasource/upload, creating an H2 datasource that uses the zip: protocol, and executing an SQL dataset path where CalciteProvider.jdbcFetchResultField calls statement.executeQuery(), causing precompiled Java aliases in test.mv.db to execute arbitrary code. This issue is fixed in version 2.10.23.

Affected products
Dataease
Fix
Available
CVSS 4.0
7.1 HIGH
EPSS
0.3% (25th percentile)
Weakness
CWE-434
NVD status
Deferred
Published
2026-07-15
CVE-2026-50124 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-50124 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-50124 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.