Executive brief
Ericsson CodeChecker is a code analysis and review platform used by development teams. An authentication vulnerability in the personal access token deletion feature allows a privileged user to delete all tokens in the system, not just their own, potentially disrupting legitimate users' access and enabling account takeover scenarios.
Technical details
The vulnerability is a SQL query scope bypass in the personal access token removal function (authentication.py, line 735). The query selects from PersonalAccessTokenDB but applies filter predicates on Session table columns without a join between the two tables. SQLAlchemy resolves this as an implicit cross join, causing the ownership filters to not properly constrain the deletion to the calling user's token. An attacker with authenticated, privileged access can exploit this to delete arbitrary personal access tokens from the system. The fix requires changing filter predicates to reference PersonalAccessTokenDB columns directly. Patched versions are not yet available.
Affected products
- Ericsson CodeChecker 6.26.0 to 6.28.2
Timeline
- 2026-08-25: disclosed
- 2026-08-26: other: NVD entry published