CVE-2026-108747
Deferred Deferred - Pending Action

Authorization Bypass in Lightdash Allows Token Deletion

Vulnerability report for CVE-2026-108747, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Lightdash through 2.556.0 contains an authorization bypass vulnerability that allows authenticated organization members to delete other users' personal access tokens by supplying their UUID. Attackers can send DELETE requests to the personal-access-tokens route with a victim's token UUID, even across organizations, to revoke it and break API integrations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Lightdash lightdash 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in Lightdash versions up to 2.556.0. It allows authenticated organization members to delete other users' personal access tokens by supplying the victim's token UUID. Attackers can send DELETE requests to the personal-access-tokens route, even across organizations, to revoke tokens and disrupt API integrations.

Detection Guidance

To detect this vulnerability, monitor Lightdash API logs for DELETE requests to the /personal-access-tokens endpoint with a victim's token UUID. Check for unauthorized cross-organization token deletions or repeated failed attempts to delete tokens.

Impact Analysis

This vulnerability can lead to denial of service for any API integrations or automations relying on the revoked token. It does not involve data exposure or code execution but can break critical integrations by removing access tokens.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling unauthorized token revocation, potentially disrupting API integrations that handle sensitive data. Unauthorized deletion of personal access tokens may lead to loss of access to critical systems, affecting data processing integrity and availability required by these regulations.

Mitigation Strategies

Immediately update Lightdash to the latest version beyond 2.556.0. If updating is not possible, restrict DELETE permissions for personal access tokens to token owners only and implement ownership validation in the delete route.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108747. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart