#VU121802 Improper Restriction of Excessive Authentication Attempts in DataEase - CVE-2026-23958
Published: January 21, 2026
DataEase
DataEase
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected application does not limit the number of password attempts. A remote attacker can exploit unmonitored API endpoints that verify JWT tokens, perform a brute-force attack and gain access to the target system.