Authentication Bypass Vulnerability in CodeChecker by Ericsson
CVE-2026-25660
9.3CRITICAL
What is CVE-2026-25660?
An authentication bypass vulnerability exists in CodeChecker, a tool used for code analysis that interacts with Clang Static Analyzer and Clang Tidy. This flaw allows attackers to gain unauthorized access by manipulating URLs that end with an authentication call, enabling them to assign arbitrary permissions to any existing user account within CodeChecker. The issue affects all versions of CodeChecker up to and including 6.27.3.
Affected Version(s)
CodeChecker 0 <= 6.27.3
