LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-32140

CVE-2026-32140 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: March 13, 2026

Dataease - Remote Code Execution

Published: March 12, 2026Updated: March 13, 2026PoC AvailableRemote Exploitable

Overview

Dataease prior to 2.10.20 contains a remote code execution caused by uncontrolled loading of attacker-supplied configuration files via the IniFile parameter in the Redshift JDBC driver, letting attackers execute code remotely, exploit requires control over JDBC URL parameters.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 48.9%(Probability of exploitation in next 30 days)

Impact

Attackers can execute arbitrary code remotely by loading malicious JDBC configuration files.

Mitigation

Upgrade to version 2.10.20 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 13, 2026

🟠 CVE-2026-32140 - High (8.8) Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to load an attacker-controlled configuration file. This configuration file can inject danger... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-32140/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 13, 2026

🟠 CVE-2026-32140 - High (8.8) Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to load an attacker-controlled configuration file. This configuration file can inject danger... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-32140/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-32140
Severity
High
CVSS Score
8.8
Type
undefined
Status
modified
EPSS
48.9%
Social Posts
2

CWE

  • CWE-22

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

48.9%Probability of exploitation in the next 30 days