What is CVE-2026-75978?
CVE-2026-75978 is a security vulnerability found in xianrendzw EasyReport up to version 2.0.17.0522_Beta. The flaw resides in the `DataSourceController.add` function in `DataSourceController.java`, where manipulation of the `queryerClass` argument leads to permission issues. Users are advised to immediately update to the latest version.
Azərbaycanca: CVE-2026-75978, xianrendzw EasyReport proqramının 2.0.17.0522_Beta versiyasına qədər olan versiyalarda aşkarlanmış təhlükəsizlik zəifliyidir. Zəiflik `DataSourceController.java` faylındakı `DataSourceController.add` funksiyasında `queryerClass` arqumentinin manipulyasiyası nəticəsində icazə problemlərinə səbəb olur. İstifadəçilərə təcili olaraq proqramı ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
In which software was CVE-2026-75978 discovered and what is the affected version range?
The vulnerability was found in xianrendzw EasyReport up to version 2.0.17.0522_Beta.
What is the technical cause of CVE-2026-75978?
The flaw is due to permission issues caused by manipulation of the `queryerClass` argument in the `DataSourceController.add` function in `DataSourceController.java`.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.