#VU126354 SQL injection in DataEase - CVE-2026-33083
Published: April 16, 2026
DataEase
DataEase
Description
The vulnerability allows a remote user to execute arbitrary SQL commands.
The vulnerability exists due to SQL injection in Order2SQLObj when processing the orderDirection parameter in dataset-related endpoints. A remote user can send a specially crafted request to execute arbitrary SQL commands.
Exploitation requires a valid session token and a valid dataset structure in the request.