A vulnerability was found in Dataease 2.10.20 . It has been declared as critical . Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard . The manipulation results in sql injection. This vulnerability is cataloged as CVE-2026-8724 . The attack may be launched remotely. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure.