Sceawere

Vulnerability Detail

CVE-2026-75978UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

EasyReport DataSourceController Permission Issue

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
3h ago
Vendor
xianrendzw
Product
EasyReport
Attack Type
Permission Issues
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController.add of the file DataSourceController.java of the component QueryerFactory. Such manipulation of the argument queryerClass leads to permission issues. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-08-19T00:16:28.810Z",
  "pubdate": "2026-08-19T00:16:28.810Z",
  "executiveSummary": "A permission-related security vulnerability has been identified in the xianrendzw EasyReport application up to version 2.0.17.0522_Beta. The flaw specifically resides within the DataSourceController.add function located in the DataSourceController.java file of the QueryerFactory component. This security deficiency arises from improper handling and manipulation of the queryerClass argument during data source configuration and creation processes. Remote attackers can exploit this vulnerability without prior authentication to bypass intended authorization checks, leading to unauthorized access and permission enforcement issues within the application architecture. The public disclosure of the exploit vector, combined with the vendor's lack of response to early issue reports, significantly elevates the risk posture for deployed instances. Threat actors possessing network access can leverage this flaw to interact with restricted backend functionalities, potentially compromising the confidentiality, integrity, and availability of the underlying reporting infrastructure. Immediate defensive actions are warranted to restrict exposure and monitor for unauthorized interaction with the vulnerable endpoint.",
  "technicalDetails": "The vulnerability is fundamentally rooted in inadequate access control validation and improper input sanitization within the DataSourceController.add function inside the DataSourceController.java file of the QueryerFactory component in xianrendzw EasyReport up to version 2.0.17.0522_Beta. Specifically, the application fails to adequately validate or restrict the values supplied to the queryerClass argument during execution paths handling data source definitions. Because the software dynamically processes this parameter without enforcing rigorous privilege and authorization boundaries, remote unauthorized users can manipulate the argument to invoke unintended operational states or bypass administrative security controls.\nThe attack flow initiates when a remote attacker crafts a malicious HTTP request directed at the vulnerable endpoint mapped to the DataSourceController.add function. The attacker includes a manipulated or unauthorized payload within the queryerClass parameter. Upon receipt, the QueryerFactory component processes the supplied class reference without performing sufficient validation against the caller's authorization context. This improper handling allows the execution flow to instantiate or interact with queryer classes that should otherwise be restricted based on user privilege levels.\nNetwork exposure is fully remote over standard web protocols, requiring no physical access to the host infrastructure. Based on the disclosed characteristics, the attack does not mandate prior authentication, lowering the barrier to entry for potential threat actors. The post-exploitation impact includes the potential exposure of sensitive database configurations, unauthorized data querying capabilities, or further systemic compromise depending on the privileges assigned to the underlying application runtime and the capabilities exposed by the manipulated queryer classes. As the vendor has not yet responded or issued an official patch, the vulnerability remains actively exploitable in all affected versions up to 2.0.17.0522_Beta."
}
CVE-2026-75978: EasyReport DataSourceController Permission Issue (MEDIUM Severity, CVSS: 6.3) - Sceawere