What is CVE-2026-75979?
A vulnerability in xianrendzw EasyReport up to version 2.0.17.0522_Beta affects the SQL Preview Endpoint due to improper neutralization of special elements in the `sqlText` argument via `execSqlText/previewSqlText` in DesignerController.java. Users should immediately upgrade EasyReport to the latest version to mitigate the risk.
Azərbaycanca: Bu boşluq xianrendzw EasyReport-un 2.0.17.0522_Beta versiyasına qədər olan versiyalarında "SQL Preview Endpoint"-də aşkarlanıb. "DesignerController.java" faylındakı `execSqlText/previewSqlText` funksiyasında `sqlText` arqumentinin düzgün təmizlənməməsi səbəbindən xüsusi simvolların neytrallaşdırılması pozulub. Dərhal EasyReport-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of xianrendzw EasyReport are affected by CVE-2026-75979?
This vulnerability affects xianrendzw EasyReport versions up to 2.0.17.0522_Beta.
Which function and file are targeted to exploit the CVE-2026-75979 vulnerability?
The vulnerability exploits the `execSqlText/previewSqlText` function in `DesignerController.java` due to improper sanitization of the `sqlText` argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.