Authorization Bypass in Lightdash Allows Token Deletion
CVE-2026-108747

2.3LOW

Key Information:

Vendor

Lightdash

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108747?

Lightdash versions up to 2.556.0 are susceptible to an authorization bypass vulnerability that enables authenticated organization members to delete personal access tokens belonging to other users. This can be executed by sending a DELETE request to the personal-access-tokens route, using the UUID of the victim's token. The flaw allows attackers to revoke tokens even across different organizations, potentially disrupting API integrations and compromising user security.

Affected Version(s)

lightdash 0 <= 2.556.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.