Sceawere
Vulnerability Detail
CVE-2026-108747UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Lightdash Unauthorized Token Revocation Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.2
- Creation Date
- 4h ago
- Vendor
- Lightdash
- Product
- lightdash
- Attack Type
- Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
Lightdash through 2.556.0 contains an authorization bypass vulnerability that allows authenticated organization members to delete other users' personal access tokens by supplying their UUID. Attackers can send DELETE requests to the personal-access-tokens route with a victim's token UUID, even across organizations, to revoke it and break API integrations.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.2",
"pubDate": "2026-10-11T13:17:19.367Z",
"pubdate": "2026-10-11T13:17:19.367Z",
"executiveSummary": "Lightdash versions up to 2.556.0 are susceptible to an authorization bypass vulnerability affecting the personal access token management module. The flaw allows any authenticated organization member to execute unauthorized DELETE requests against the application API to revoke personal access tokens belonging to other users, including those residing in separate organizations. This vulnerability represents a significant security risk, as it permits attackers to perform denial-of-service (DoS) operations against API integrations and automated services relying on valid tokens. Exploitation requires no elevated administrative privileges; a standard authenticated session is sufficient to target arbitrary token UUIDs. The lack of proper server-side authorization checks during the deletion request processing enables cross-user and cross-organization resource tampering, leading to potential service disruption and the invalidation of security credentials.",
"technicalDetails": "The vulnerability resides within the Lightdash personal access token management endpoint, specifically in the logic handling DELETE requests for token revocation. The root cause is a failure to implement robust server-side authorization verification when processing requests to the personal-access-tokens route. Although the API requires a valid user session, the system fails to validate whether the requester possesses ownership of the specific token UUID referenced in the request payload or URL parameter.\nThe exploitation flow begins with an authenticated attacker obtaining the UUID of a target user's personal access token. Given that these UUIDs may be discoverable via secondary information disclosure vectors or predictive analysis, the attacker crafts a malicious HTTP DELETE request targeting the affected personal-access-tokens route. Because the backend service lacks a check to verify that the 'userId' associated with the token matches the 'userId' of the authenticated session, the application processes the request as a legitimate administrative or owner-initiated action.\nOnce the DELETE request is successfully routed to the backend, the application logic proceeds to invalidate or remove the record associated with the supplied UUID from the database. This behavior bypasses traditional multi-tenancy and resource-level access controls, effectively allowing a user to move laterally across organizational boundaries to target any token registered within the instance. The impact of this exploit is the immediate termination of the target's API integration, which may cause critical failures in dependent automated workflows, data pipelines, or third-party service connections.\nThe vulnerable component is the REST API handler responsible for managing user-scoped security credentials. The exposure is limited to authenticated users; however, the lack of granular object-level permission checks (such as ensuring the requestor is the owner or an instance-wide administrator) means that the scope of the vulnerability includes all users within the Lightdash ecosystem. The vulnerability is present in all versions up to and including 2.556.0. No specific network exposure is required beyond connectivity to the application's API gateway, and no specialized exploit payloads are needed beyond the targeted token UUID, making this a highly accessible authorization bypass flaw."
}