Lightdash through 2.556.0 contains an authorization bypass vulnerability that allows authenticated organization members to delete other users' personal access tokens by supplying their UUID. Attackers can send DELETE requests to the personal-access-tokens route with a victim's token UUID, even across organizations, to revoke it and break API integrations.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lightdash
Lightdash lightdash |
|
| Vendors & Products |
Lightdash
Lightdash lightdash |
Sun, 11 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lightdash through 2.556.0 contains an authorization bypass vulnerability that allows authenticated organization members to delete other users' personal access tokens by supplying their UUID. Attackers can send DELETE requests to the personal-access-tokens route with a victim's token UUID, even across organizations, to revoke it and break API integrations. | |
| Title | Lightdash through 2.556.0 Authorization Bypass via Personal Access Token Deletion | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T12:19:48.672Z
Reserved: 2026-10-11T01:53:21.164Z
Link: CVE-2026-108747
No data.
Status : Deferred
Published: 2026-10-11T13:17:19.367
Modified: 2026-10-11T13:17:19.480
Link: CVE-2026-108747
No data.
OpenCVE Enrichment
Updated: 2026-10-11T14:45:07Z
Weaknesses