Authentication bypass occurs when the URL ends with Authentication with certain function calls. This bypass allows assigning arbitrary permission to any user existing in CodeChecker.
This issue affects CodeChecker: through 6.27.3.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 24 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the URL ends with Authentication with certain function calls. This bypass allows assigning arbitrary permission to any user existing in CodeChecker. This issue affects CodeChecker: through 6.27.3. | |
| Title | Authentication bypass for certain API calls | |
| Weaknesses | CWE-290 CWE-863 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: ERIC
Published:
Updated: 2026-04-24T13:51:11.174Z
Reserved: 2026-02-04T12:41:54.869Z
Link: CVE-2026-25660
Updated: 2026-04-24T13:51:03.368Z
Status : Awaiting Analysis
Published: 2026-04-24T14:16:18.127
Modified: 2026-04-24T14:39:28.770
Link: CVE-2026-25660
No data.
OpenCVE Enrichment
No data.