PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108747 Lightdash CVE debrief

Lightdash through 2.556.0 contains an authorization bypass vulnerability that allows authenticated organization members to delete other users' personal access tokens by supplying their UUID. This vulnerability can be exploited by sending DELETE requests to the personal-access-tokens route with a victim's token UUID, even across organizations, potentially disrupting API integrations and affecting user access to the system. Defenders responsible for Lightdash deployments should assess exposure and prioritize remediation, especially in environments where multiple organization members have access to the system.

Vendor
Lightdash
Product
Unknown
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for Lightdash deployments, especially in environments where multiple organization members have access to the system, should assess exposure and prioritize remediation.

Why it matters

The CVE-2026-108747 vulnerability in Lightdash through 2.556.0 allows authenticated organization members to delete other users' personal access tokens. Defenders should prioritize verifying and remediating this vulnerability in their Lightdash deployments.

  • An attacker could delete personal access tokens, potentially disrupting API integrations.
  • An attacker could delete personal access tokens, potentially affecting user access to the system.
  • Defenders need to verify the Lightdash version and ensure it is not vulnerable.

Technical summary

The vulnerability allows authenticated organization members to delete other users' personal access tokens by supplying their UUID. This can be done by sending DELETE requests to the personal-access-tokens route with a victim's token UUID, even across organizations. The vulnerability affects Lightdash through 2.556.0 and can be used to disrupt API integrations and affect user access to the system. Defenders should prioritize verifying and remediating this vulnerability in their Lightdash deployments, especially in environments where multiple organization members have access to the system.

Defensive priority

Defenders should prioritize verifying and remediating this vulnerability in their Lightdash deployments, especially in environments where multiple organization members have access to the system.

Recommended defensive actions

  • Verify the Lightdash version and ensure it is not vulnerable (less than or equal to 2.556.0).
  • Restrict access to the personal-access-tokens route to prevent unauthorized deletion of personal access tokens.
  • Monitor for suspicious activity related to personal access token deletion.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and source item provide details on the authorization bypass vulnerability in Lightdash through 2.556.0. The vulnerability allows authenticated organization members to delete other users' personal access tokens by supplying their UUID.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108747 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108747

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108747 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108747

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Lightdash through 2.556.0 Authorization Bypass via Personal Access Token Deletion

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108747.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://hackmd.io/@haind03/lightdash-pat-delete-ownership-bypass-20261011

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/lightdash/lightdash/blob/c890f0b982efb51f1f8d1535d4e334447cec2ed7/packages/backend/src/services/PersonalAccessTokenService.ts

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/lightdash/lightdash/blob/c890f0b982efb51f1f8d1535d4e334447cec2ed7/packages/backend/src/models/DashboardModel/PersonalAccessTokenModel.ts

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/lightdash/lightdash

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/lightdash-through-2.556.0-authorization-bypass-via-personal-access-token-deletion

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.