Medium severity4.2NVD Advisory· Published Oct 11, 2026· Updated Oct 11, 2026
CVE-2026-108747
CVE-2026-108747
Description
Lightdash through 2.556.0 contains an authorization bypass vulnerability that allows authenticated organization members to delete other users' personal access tokens by supplying their UUID. Attackers can send DELETE requests to the personal-access-tokens route with a victim's token UUID, even across organizations, to revoke it and break API integrations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/lightdash/lightdash/blob/c890f0b982efb51f1f8d1535d4e334447cec2ed7/packages/backend/src/models/DashboardModel/PersonalAccessTokenModel.tsnvd
- github.com/lightdash/lightdash/blob/c890f0b982efb51f1f8d1535d4e334447cec2ed7/packages/backend/src/services/PersonalAccessTokenService.tsnvd
- hackmd.io/@haind03/lightdash-pat-delete-ownership-bypass-20261011nvd
- www.vulncheck.com/advisories/lightdash-through-2.556.0-authorization-bypass-via-personal-access-token-deletionnvd
News mentions
0No linked articles in our index yet.