#VU126353 SQL injection in DataEase - CVE-2026-33084
Published: April 16, 2026
DataEase
DataEase
Description
The vulnerability allows a remote user to perform time-based blind SQL injection.
The vulnerability exists due to SQL injection in the getFieldEnumObj endpoint when handling a POST request to /de2api/datasetData/enumValueObj with a crafted sort parameter in the JSON body. A remote user can send a specially crafted request to perform time-based blind SQL injection.
Exploitation requires a valid X-DE-TOKEN and knowledge of a target queryId and datasetGroupId.