PatchSiren cyber security CVE debrief
CVE-2026-108747 Lightdash CVE debrief
Lightdash through 2.556.0 contains an authorization bypass vulnerability that allows authenticated organization members to delete other users' personal access tokens by supplying their UUID. This vulnerability can be exploited by sending DELETE requests to the personal-access-tokens route with a victim's token UUID, even across organizations, potentially disrupting API integrations and affecting user access to the system. Defenders responsible for Lightdash deployments should assess exposure and prioritize remediation, especially in environments where multiple organization members have access to the system.
- Vendor
- Lightdash
- Product
- Unknown
- CVSS
- LOW 2.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for Lightdash deployments, especially in environments where multiple organization members have access to the system, should assess exposure and prioritize remediation.
Why it matters
The CVE-2026-108747 vulnerability in Lightdash through 2.556.0 allows authenticated organization members to delete other users' personal access tokens. Defenders should prioritize verifying and remediating this vulnerability in their Lightdash deployments.
- An attacker could delete personal access tokens, potentially disrupting API integrations.
- An attacker could delete personal access tokens, potentially affecting user access to the system.
- Defenders need to verify the Lightdash version and ensure it is not vulnerable.
Technical summary
The vulnerability allows authenticated organization members to delete other users' personal access tokens by supplying their UUID. This can be done by sending DELETE requests to the personal-access-tokens route with a victim's token UUID, even across organizations. The vulnerability affects Lightdash through 2.556.0 and can be used to disrupt API integrations and affect user access to the system. Defenders should prioritize verifying and remediating this vulnerability in their Lightdash deployments, especially in environments where multiple organization members have access to the system.
Defensive priority
Defenders should prioritize verifying and remediating this vulnerability in their Lightdash deployments, especially in environments where multiple organization members have access to the system.
Recommended defensive actions
- Verify the Lightdash version and ensure it is not vulnerable (less than or equal to 2.556.0).
- Restrict access to the personal-access-tokens route to prevent unauthorized deletion of personal access tokens.
- Monitor for suspicious activity related to personal access token deletion.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and source item provide details on the authorization bypass vulnerability in Lightdash through 2.556.0. The vulnerability allows authenticated organization members to delete other users' personal access tokens by supplying their UUID.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108747 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108747
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108747 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108747
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Lightdash through 2.556.0 Authorization Bypass via Personal Access Token Deletion
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108747.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://hackmd.io/@haind03/lightdash-pat-delete-ownership-bypass-20261011
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/lightdash/lightdash/blob/c890f0b982efb51f1f8d1535d4e334447cec2ed7/packages/backend/src/services/PersonalAccessTokenService.ts
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/lightdash/lightdash/blob/c890f0b982efb51f1f8d1535d4e334447cec2ed7/packages/backend/src/models/DashboardModel/PersonalAccessTokenModel.ts
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/lightdash/lightdash
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/lightdash-through-2.556.0-authorization-bypass-via-personal-access-token-deletion
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.