# CVE-2026-90529

## Summary

- **CVE ID:** CVE-2026-90529
- **Severity:** MEDIUM
- **CVSS Score:** 5.1 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X)
- **CWE:** CWE-79, CWE-94
- **Published:** Sep 13, 2026
- **Last Modified:** Sep 15, 2026

## Description

A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument canvasViewInfo[*].customAttr.tooltip.backgroundColor leads to cross site scripting. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.

## Affected Products

- n/a — DataEase (2.10.0)
- n/a — DataEase (2.10.1)
- n/a — DataEase (2.10.2)
- n/a — DataEase (2.10.3)
- n/a — DataEase (2.10.4)
- n/a — DataEase (2.10.5)
- n/a — DataEase (2.10.6)
- n/a — DataEase (2.10.7)
- n/a — DataEase (2.10.8)
- n/a — DataEase (2.10.9)
- n/a — DataEase (2.10.10)
- n/a — DataEase (2.10.11)
- n/a — DataEase (2.10.12)
- n/a — DataEase (2.10.13)
- n/a — DataEase (2.10.14)
- n/a — DataEase (2.10.15)
- n/a — DataEase (2.10.16)
- n/a — DataEase (2.10.17)
- n/a — DataEase (2.10.18)
- n/a — DataEase (2.10.19)
- n/a — DataEase (2.10.20)
- n/a — DataEase (2.10.21)
- n/a — DataEase (2.10.22)
- n/a — DataEase (2.10.23)
- n/a — DataEase (2.10.24)
- n/a — DataEase (2.10.25)
- n/a — DataEase (2.10.26)

## References

- [CNA](https://vuldb.com/vuln/403119)
- [CNA](https://vuldb.com/vuln/403119/cti)
- [CNA](https://vuldb.com/cve/CVE-2026-90529)
- [CNA](https://vuldb.com/submit/912538)
- [CNA](https://github.com/dataease/dataease/issues/18846)
- [CNA](https://github.com/dataease/dataease/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 9.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._