Executive brief
Qt Axivion, a tool used for software static analysis and architecture protection, contains a security flaw in its Dashboard management interface. An authorized user could exploit an undocumented programming interface to grant themselves administrative privileges. In the worst case, this could allow an attacker to take full control of the Dashboard or execute malicious code on the underlying server, potentially compromising sensitive source code analysis data.
Technical details
A missing authorization check exists in an undocumented internal API endpoint (POST /api/users/~/{user}/tokens) within the Axivion Dashboard. An attacker with existing low-privileged access via OAuth/OIDC can forge a request to create an API token for a different, higher-privileged user (such as an administrator) by knowing their login name. By finalizing the token creation with their own valid session, the attacker can assume the identity of the target user. When combined with other system weaknesses, this privilege escalation can lead to arbitrary code execution on the host operating system under the context of the Dashboard server process. Patches are available in versions 7.9.13, 7.10.11, 7.11.7, and 7.12.2.
Affected products
- Qt Axivion 7.8.5 to 7.8.12, 7.9.0 to 7.9.12, 7.10.0 to 7.10.10, 7.11.0 to 7.11.6, 7.12.0 to 7.12.1
Timeline
- 2026-07-09: advisory: Initial disclosure by Qt and NVD publication
- 2026-07-09: patched: Fixes released in multiple maintenance branches