Home

Description

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the URL ends with Authentication with certain function calls. This bypass allows assigning arbitrary permission to any user existing in CodeChecker. This issue affects CodeChecker: through 6.27.3.

PUBLISHED Reserved 2026-02-04 | Published 2026-04-24 | Updated 2026-04-24 | Assigner ERIC




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/S:N/AU:Y/R:U/V:C/RE:M/U:Red

Problem types

CWE-290 Authentication bypass by spoofing

CWE-863 Incorrect Authorization

Product status

Default status
unaffected

Any version
affected

Credits

Scott Tolley finder

References

github.com/...hecker/security/advisories/GHSA-4v9x-cqc5-j645 vendor-advisory

cve.org (CVE-2026-25660)

nvd.nist.gov (CVE-2026-25660)

Download JSON