CVE-2026-25660
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the URL ends with Authentication with certain function calls. This bypass allows assigning arbitrary permission to any user existing in CodeChecker. This issue affects CodeChecker: through 6.27.3.
View on NVDAnalysis
CodeChecker, a popular tool for managing Clang Static Analyzer and Clang Tidy results, is vulnerable to a critical authentication bypass in versions up to 6.27.3. Attackers can exploit specific URL patterns to bypass authentication and assign themselves administrative permissions. Development teams using CodeChecker to track code defects should update to a patched version immediately.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCWE-290CWE-863EPSS
Affects
ericsson:codecheckerTechnical description
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the URL ends with Authentication with certain function calls. This bypass allows assigning arbitrary permission to any user existing in CodeChecker. This issue affects CodeChecker: through 6.27.3.