DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values to TokenUtils.validate(), which checks only token presence and length before userBOByToken(token) uses JWT.decode() without signature verification, allowing forged tokens with chosen uid and oid values to be accepted when licenseValid=true. This issue is fixed in version 2.10.23.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46684.json",
"cwe_ids": [
"CWE-347"
],
"cna_assigner": "GitHub_M"
}[
{
"id": "CVE-2026-46684-05e79d4e",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/substitute/permissions/login/SubstituleLoginServer.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"101400650825182765908241710975950805432",
"148810183135062078404876729302986570238",
"317666980782953759517652185240160066897",
"198274242159546448855848860116021167177",
"291774557083734564573748448374219740441",
"165751206156248577619155997008149171012",
"107557370441788502157768238133289210358",
"179266153673572914841534749699434243430",
"36021612818728191741751065537386073242"
]
},
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/3efda9d29c0df4300d43bb7874638e03060c3e2d",
"signature_type": "Line"
},
{
"id": "CVE-2026-46684-1411d0a0",
"target": {
"function": "doFilter",
"file": "sdk/common/src/main/java/io/dataease/auth/filter/CommunityTokenFilter.java"
},
"deprecated": false,
"digest": {
"function_hash": "252246884505931591444109738966086319864",
"length": 1639.0
},
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/3efda9d29c0df4300d43bb7874638e03060c3e2d",
"signature_type": "Function"
},
{
"id": "CVE-2026-46684-2396f5a0",
"target": {
"function": "localLogin",
"file": "core/core-backend/src/main/java/io/dataease/substitute/permissions/login/SubstituleLoginServer.java"
},
"deprecated": false,
"digest": {
"function_hash": "60220872449320740080856685057957256901",
"length": 654.0
},
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/3efda9d29c0df4300d43bb7874638e03060c3e2d",
"signature_type": "Function"
},
{
"id": "CVE-2026-46684-40ddc69a",
"target": {
"file": "sdk/common/src/main/java/io/dataease/auth/filter/CommunityTokenFilter.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"26286723902899925141725075466550219026",
"267311974290102092317574339670310283566",
"332200611652247150607146089147829509402",
"249797997018617793903261139739124924463",
"156569737060090805735364025134991355370"
]
},
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/3efda9d29c0df4300d43bb7874638e03060c3e2d",
"signature_type": "Line"
},
{
"id": "CVE-2026-46684-419dbc95",
"target": {
"file": "sdk/common/src/main/java/io/dataease/auth/config/SubstituleLoginConfig.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"238925653931828016421770412181852730458",
"32399763719502675272019205160712957998",
"48922569995342750495116332236771450521",
"29076182356656558675007035548627996508",
"117364898578898186122955762710347159457",
"198182111032079548776903510618844408021",
"55082313116490143590725018205269552124",
"129436292320335456158599710380197568762",
"31008009504663775394605205307807952731",
"296892119215784213129948230518287195591",
"269626892227725263533430198733338751565",
"70994046822198366596514629400659711080",
"122721267797409380528476564205398970473",
"6336893576826341722296321237084100327",
"248493086956179005727037205585871287315",
"68328513864524157088309782784318609599",
"106166362245271812573375610730940728346",
"244575647132183409767252302623444544640",
"177141818934975315460008368767096452332",
"148135213546180463239510150398453357598",
"339522341375673707302207132516525072851",
"245443068605628018796336837027876319840",
"158622589273667537435112975405888416924",
"244891232964963265628990557085125097179",
"235531408303476902536337185705500264029",
"166610632109632817845420438715674237398",
"318131933898678690858524992355748172778",
"336053783405571223398931046985136081362",
"271302589586774231267657110964773108226",
"299922968278000854083885297460654288348",
"166438181779697640669455140887379430010",
"240360472784716698467858980641359151032",
"322070125752639093723555721851760083019",
"173217674230365910452527573457338027789",
"215609011333308873839989242208963381563",
"117171491135299685831571927928961427968",
"117804625911335599917612736332018785126",
"165127357945033177147383935241560233775",
"62115079892362602524140903821220573722",
"139386594293239423279076423504777319193",
"71062217409851758447715881866209631731",
"54319346519630393684903176458770735275",
"61660963510391987910204029378894124975",
"49146245765929600424322798043441331323",
"214251858486523450111253579660312648735",
"5098170686438575384566457266170545967",
"236514192558806013114943615418172243395"
]
},
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/3efda9d29c0df4300d43bb7874638e03060c3e2d",
"signature_type": "Line"
},
{
"id": "CVE-2026-46684-78a7153f",
"target": {
"function": "modifyPwd",
"file": "sdk/common/src/main/java/io/dataease/auth/config/SubstituleLoginConfig.java"
},
"deprecated": false,
"digest": {
"function_hash": "166072074041023540874663560159062219518",
"length": 382.0
},
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/3efda9d29c0df4300d43bb7874638e03060c3e2d",
"signature_type": "Function"
},
{
"id": "CVE-2026-46684-da0836f8",
"target": {
"function": "substituleLoginData",
"file": "sdk/common/src/main/java/io/dataease/auth/config/SubstituleLoginConfig.java"
},
"deprecated": false,
"digest": {
"function_hash": "130302350935559486088362554432695615815",
"length": 334.0
},
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/3efda9d29c0df4300d43bb7874638e03060c3e2d",
"signature_type": "Function"
},
{
"id": "CVE-2026-46684-f974ea58",
"target": {
"function": "getPwd",
"file": "sdk/common/src/main/java/io/dataease/auth/config/SubstituleLoginConfig.java"
},
"deprecated": false,
"digest": {
"function_hash": "139414722809112031103190387611025682223",
"length": 349.0
},
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/3efda9d29c0df4300d43bb7874638e03060c3e2d",
"signature_type": "Function"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46684.json"
"2026-08-12T16:25:20Z"