CVE-2026-32140 | Dataease up to 2.10.19 JDBC Driver rsjdbc.ini getJdbcIniFile path traversal (GHSA-jc9q-3jfw-mch4)
A vulnerability classified as critical has been found in Dataease up to 2.10.19. The affected element is the function getJdbcIniFile of the file rsjdbc.ini of the component JDBC Driver. The manipulation of the argument IniFile leads to path traversal.
This vulnerability is documented as CVE-2026-32140. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.