Impact
The vulnerability, classified as CWE-639, enables an authenticated organization member to delete the personal access tokens of other users by supplying the victim’s UUID. An attacker can issue DELETE requests to the personal‑access‑tokens API endpoint and revoke a target user’s token, even across different organizations. This bypasses normal authorization controls and results in unauthorized removal of authentication credentials, disrupting API integrations and potentially causing service outages.
Affected Systems
The issue affects Lightdash versions up to and including 2.556.0. Any deployment of these versions that allows users to perform authenticated API calls is susceptible. No sub‑version range is specified beyond the maximum version.
Risk and Exploitability
The CVSS score is 2.3, indicating low severity. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation is documented. However, because the attacker only needs authenticated access within the organization, the risk arises primarily from mis‑assigned roles or lack of least‑privilege enforcement. The impact is limited to token revocation, which can break integrations but does not grant broader access to the system.
OpenCVE Enrichment