๐Ÿ” CVE Alert

CVE-2026-93660

MEDIUM 6.5

SQLBot through 1.10.1 Improper Access Control via Dashboard Update

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary dashboard IDs to rename dashboards and overwrite component data, canvas styles, and view information belonging to other workspace members.

CWE CWE-639
Vendor dataease
Product sqlbot
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for dataease sqlbot

Be the first to know when new medium vulnerabilities affecting dataease sqlbot are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

dataease / SQLBot
0 โ‰ค 1.10.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/dataease/SQLBot/issues/1377 github.com: https://github.com/dataease/SQLBot/commit/fccdd29421dfc32d3a552ab29b2554974e1ebc4c github.com: https://github.com/dataease/SQLBot/blob/v1.10.1/backend/apps/dashboard/crud/dashboard_service.py github.com: https://github.com/dataease/SQLBot/blob/v1.10.1/backend/apps/system/schemas/permission.py github.com: https://github.com/dataease/SQLBot vulncheck.com: https://www.vulncheck.com/advisories/sqlbot-through-1.10.1-improper-access-control-via-dashboard-update

Credits

George Chen