CVE-2026-75978
Last modified
CVE-2026-75978 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController.add of the file DataSourceController.java of the component QueryerFactory. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController.add of the file DataSourceController.java of the component QueryerFactory. Such manipulation of the argument queryerClass leads to permission issues. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| xianrendzw | EasyReport | 2.0.17.0522_Beta |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-75978?
How severe is CVE-2026-75978?
How do I fix CVE-2026-75978?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-75966The Podlove Podcast Publisher plugin for WordPress is vulner…6.4
- CVE-2026-7597A vulnerability was found in mem0ai mem0 up to 1.0.11. This …6.3
- CVE-2026-75971The ShopEngine Elementor WooCommerce Builder Addon – All in …7.2
- CVE-2026-75975fast-uri is a URI parser for Node.js. Its custom parser for …7.5
- CVE-2026-75976A weakness has been identified in TRENDnet TEW-823DRU 1.1.02…9.9
- CVE-2026-75977The Mang Board WP plugin for WordPress is vulnerable to Miss…8.8
- CVE-2026-75979A vulnerability was found in xianrendzw EasyReport up to 2.0…6.3
- CVE-2026-7598A security vulnerability has been detected in libssh2 up to …7.3
- CVE-2026-75980The BetterDocs – AI Documentation, Knowledge Base, Docs, Wik…6.4
- CVE-2026-75981The TranslatePress – Translate Multilingual sites with AI Tr…7.2
- CVE-2026-75982The LearnPress plugin for WordPress is vulnerable to unautho…4.4
- CVE-2026-75984A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b0…7.4
Are you affected by CVE-2026-75978?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
