Authentication Bypass Vulnerability in CodeChecker by Ericsson
CVE-2026-25660

9.3CRITICAL

Key Information:

Vendor

Ericsson

Vendor
CVE Published:
24 April 2026

What is CVE-2026-25660?

An authentication bypass vulnerability exists in CodeChecker, a tool used for code analysis that interacts with Clang Static Analyzer and Clang Tidy. This flaw allows attackers to gain unauthorized access by manipulating URLs that end with an authentication call, enabling them to assign arbitrary permissions to any existing user account within CodeChecker. The issue affects all versions of CodeChecker up to and including 6.27.3.

Affected Version(s)

CodeChecker 0 <= 6.27.3

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Scott Tolley
.