CVE-2023-35164: Dataease

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions a missing authorization check allows unauthorized users to manipulate a dashboard created by the administrator. This vulnerability has been fixed in version 1.18.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected products

  • Dataease Dataease: before 1.18.8 (fixed in 1.18.8)

Published 2023-06-26. Last modified 2026-06-17.