Authorization Bypass in Lightdash Allows Token Deletion
CVE-2026-108747
2.3LOW
What is CVE-2026-108747?
Lightdash versions up to 2.556.0 are susceptible to an authorization bypass vulnerability that enables authenticated organization members to delete personal access tokens belonging to other users. This can be executed by sending a DELETE request to the personal-access-tokens route, using the UUID of the victim's token. The flaw allows attackers to revoke tokens even across different organizations, potentially disrupting API integrations and compromising user security.
Affected Version(s)
lightdash 0 <= 2.556.0
References
CVSS V4
Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
