Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40901

29
FAUCET Score

CVE-2026-40901 affects DataEase, an open-source data visualization platform, in versions 2.10.20 and earlier. The vulnerability stems from unsafe Java deserialization in the bundled Quartz scheduler library, which deserializes job data from the database without filtering or validation. An authenticated attacker with database write access can inject a malicious CommonsCollections6 gadget chain payload into scheduled job configurations, leading to arbitrary command execution with root privileges when the cron trigger fires. The vulnerability carries a CVSS score of 8.8 (HIGH) with a network attack vector, low complexity, and requirement for low privilege authentication. Successful exploitation results in complete compromise of confidentiality, integrity, and availability, with the attacker gaining root-level code execution within the container environment. The attack chain leverages legacy deserialization gadgets present in bundled velocity and commons-collections libraries. There is currently no evidence of active exploitation in the wild, and the vulnerability is not present on the CISA Known Exploited Vulnerabilities list. Community attention remains minimal, with an EPSS score of 0.0035 indicating very low prevalence of exploitation attempts. The issue has been remediated in version 2.10.21, and organizations running affected versions should prioritize patching to eliminate the deserialization gadget chains.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.10.21CPE matchmatch criteria
cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.5HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.63%
Probability of exploitation in next 30 days
EPSS Percentile
46.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0063 is in the 37th percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / dataease/dataease/releases/tag/v2.10.21
Release Notes
github.com / dataease/dataease/security/advisories/GHSA-gm5q-g72w-c466
ExploitThird Party Advisory