A vulnerability categorized as critical has been discovered in Dataease up to 2.10.19. Affected by this issue is some unknown functionality of the file /de2api/datasource/previewData. The manipulation of the argument table results in sql injection.

This vulnerability is identified as CVE-2026-32137. The attack can be executed remotely. There is not any exploit available.

It is advisable to upgrade the affected component.