Description
Lightdash through 2.556.0 contains an authorization bypass vulnerability that allows authenticated organization members to delete other users' personal access tokens by supplying their UUID. Attackers can send DELETE requests to the personal-access-tokens route with a victim's token UUID, even across organizations, to revoke it and break API integrations.
Published: 2026-10-11
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: Unauthorized PAT Deletion
Action: Patch Now
AI Analysis

Impact

The vulnerability, classified as CWE-639, enables an authenticated organization member to delete the personal access tokens of other users by supplying the victim’s UUID. An attacker can issue DELETE requests to the personal‑access‑tokens API endpoint and revoke a target user’s token, even across different organizations. This bypasses normal authorization controls and results in unauthorized removal of authentication credentials, disrupting API integrations and potentially causing service outages.

Affected Systems

The issue affects Lightdash versions up to and including 2.556.0. Any deployment of these versions that allows users to perform authenticated API calls is susceptible. No sub‑version range is specified beyond the maximum version.

Risk and Exploitability

The CVSS score is 2.3, indicating low severity. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation is documented. However, because the attacker only needs authenticated access within the organization, the risk arises primarily from mis‑assigned roles or lack of least‑privilege enforcement. The impact is limited to token revocation, which can break integrations but does not grant broader access to the system.

Generated by OpenCVE AI on October 11, 2026 at 14:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Lightdash to a patched release such as 2.556.1 or later.
  • Enforce role boundaries so that only authorized users can access PAT deletion endpoints.
  • Revoke or rotate personal access tokens that may have been exposed and monitor audit logs for unauthorized DELETE requests.
  • If an upgrade is not immediately possible, disable the DELETE PAT endpoint for all but administrators or restrict API access through network segmentation.

Generated by OpenCVE AI on October 11, 2026 at 14:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Lightdash
Lightdash lightdash
Vendors & Products Lightdash
Lightdash lightdash

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Lightdash through 2.556.0 contains an authorization bypass vulnerability that allows authenticated organization members to delete other users' personal access tokens by supplying their UUID. Attackers can send DELETE requests to the personal-access-tokens route with a victim's token UUID, even across organizations, to revoke it and break API integrations.
Title Lightdash through 2.556.0 Authorization Bypass via Personal Access Token Deletion
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Lightdash Lightdash
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:48.672Z

Reserved: 2026-10-11T01:53:21.164Z

Link: CVE-2026-108747

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-11T13:17:19.367

Modified: 2026-10-11T13:17:19.480

Link: CVE-2026-108747

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:15:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key