CVE-2026-40901 affects DataEase, an open-source data visualization platform, in versions 2.10.20 and earlier. The vulnerability stems from unsafe Java deserialization in the bundled Quartz scheduler library, which deserializes job data from the database without filtering or validation. An authenticated attacker with database write access can inject a malicious CommonsCollections6 gadget chain payload into scheduled job configurations, leading to arbitrary command execution with root privileges when the cron trigger fires. The vulnerability carries a CVSS score of 8.8 (HIGH) with a network attack vector, low complexity, and requirement for low privilege authentication. Successful exploitation results in complete compromise of confidentiality, integrity, and availability, with the attacker gaining root-level code execution within the container environment. The attack chain leverages legacy deserialization gadgets present in bundled velocity and commons-collections libraries. There is currently no evidence of active exploitation in the wild, and the vulnerability is not present on the CISA Known Exploited Vulnerabilities list. Community attention remains minimal, with an EPSS score of 0.0035 indicating very low prevalence of exploitation attempts. The issue has been remediated in version 2.10.21, and organizations running affected versions should prioritize patching to eliminate the deserialization gadget chains.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.10.21CPE matchmatch criteria | cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.