CVE-2025-70829
CWE-200Published: February 17, 2026· Updated: Feb 23, 2026
Official Description
An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection string.
Technical Analysis
CVE-2025-70829 requires adjacent network access, limiting remote exploitation but still posing risk in shared or local network environments.
Exploitation requires low privileges, which limits the exposure to scenarios where an attacker has already gained initial access.
A successful exploit results in complete confidentiality breach (data exposure), with a CVSS base score of 5.7.
A proof-of-concept (PoC) exploit exists for CVE-2025-70829. While not yet confirmed in active campaigns, the availability of PoC code increases exploitation risk substantially.
From a weakness classification perspective (CWE-200): Information exposure vulnerabilities leak sensitive data to unauthorized actors.
CVSS v3.1 Vector Breakdown
Affected Vendors & Products
Exploit & PoC Resources
Official Patches & Advisories
All References (2)
Quick Facts
Related CVEs (CWE-200)
Recommended Actions
- →Apply vendor patches immediately
- →Monitor CVE-2025-70829 in threat intel feeds
- →Review IDS/IPS signatures for exploitation attempts