Authentication bypass occurs when the URL ends with Authentication with certain function calls. This bypass allows assigning arbitrary permission to any user existing in CodeChecker.
This issue affects CodeChecker: through 6.27.3.
Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 24 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the URL ends with Authentication with certain function calls. This bypass allows assigning arbitrary permission to any user existing in CodeChecker. This issue affects CodeChecker: through 6.27.3. | |
| Title | Authentication bypass for certain API calls | |
| Weaknesses | CWE-290 CWE-863 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ERIC
Published:
Updated: 2026-04-24T13:51:11.174Z
Reserved: 2026-02-04T12:41:54.869Z
Link: CVE-2026-25660
Updated: 2026-04-24T13:51:03.368Z
Status : Awaiting Analysis
Published: 2026-04-24T14:16:18.127
Modified: 2026-04-24T14:39:28.770
Link: CVE-2026-25660
No data.
OpenCVE Enrichment
No data.