PT-2026-3770 · Dataease · Dataease

Mosesox

+1

·

Published

2026-01-21

·

Updated

2026-02-17

·

CVE-2026-23958

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dataease versions prior to 2.10.19
Description Dataease, an open source data visualization analysis tool, is susceptible to an account takeover issue. The tool utilizes the MD5 hash of a user’s password as the JWT signing secret. This predictable secret derivation allows an attacker to brute-force an administrator’s password by exploiting unmonitored API endpoints that verify JWT tokens.
Recommendations Update to version 2.10.19 or later.

Exploit

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2026-23958
GHSA-5WVM-4M4Q-RH7J

Affected Products

Dataease