TopVuln

High-risk vulnerability digests

CVE-2026-40901

  • HIGH

Details

CVSS v4
7.5
NVD published
2026-04-16 21:16:24
EPSS
0.4% probability · 57.7th percentile — 2026-05-12
Affected versions
DataEase 2.10.20 and below
Summary
DataEase open-source data visualization platform bundles vulnerable legacy libraries that enable insecure deserialization of untrusted data. An authenticated attacker with write access to the Quartz job table can inject a malicious deserialization gadget chain payload. When the scheduled job triggers, the payload executes arbitrary code as root on the affected server, leading to full system compromise.
Remediation
Upgrade DataEase to version 2.10.21 or later to resolve this vulnerability. Restrict untrusted access to the DataEase application and its underlying database until patching is completed.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.