CVE-2026-32137: Dataease

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasource/previewData is directly concatenated into the SQL statement without any filtering or parameterization. Since tableName is a user-controllable string, attackers can inject malicious SQL statements by constructing malicious table names. This vulnerability is fixed in 2.10.20.

Affected products

  • Dataease Dataease: before 2.10.20 (fixed in 2.10.20)

Published 2026-03-12. Last modified 2026-06-17.