Description
Lightdash through 2.556.0 contains an authorization bypass vulnerability that allows authenticated organization members to delete other users' personal access tokens by supplying their UUID. Attackers can send DELETE requests to the personal-access-tokens route with a victim's token UUID, even across organizations, to revoke it and break API integrations.
Published: 2026-10-11
Score: 2.3 Low
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Lightdash
Lightdash lightdash
Vendors & Products Lightdash
Lightdash lightdash

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Lightdash through 2.556.0 contains an authorization bypass vulnerability that allows authenticated organization members to delete other users' personal access tokens by supplying their UUID. Attackers can send DELETE requests to the personal-access-tokens route with a victim's token UUID, even across organizations, to revoke it and break API integrations.
Title Lightdash through 2.556.0 Authorization Bypass via Personal Access Token Deletion
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Lightdash Lightdash
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:48.672Z

Reserved: 2026-10-11T01:53:21.164Z

Link: CVE-2026-108747

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-11T13:17:19.367

Modified: 2026-10-11T13:17:19.480

Link: CVE-2026-108747

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:15:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key