CRITICAL🇵🇱 Wersja polska

CVE-2026-25660

CVSS 9.3v4.0pub. 2026-04-24upd. 2026-04-27

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the URL ends with Authentication with certain function calls.  This bypass allows assigning arbitrary permission to any user existing in CodeChecker. This issue affects CodeChecker: through 6.27.3.

🤖 AI Analysis
How it works

The vulnerability (CWE-290, CWE-863) consists of improper identity verification and authorization in certain function calls when the URL ends with a string related to the authentication process. The application incorrectly treats such a request as authorized, bypassing proper access control. As a result, an attacker without any credentials can issue administrative requests concerning user permissions.

Impact

An attacker can grant any existing user in the CodeChecker system unlimited or administrative privileges, which in practice leads to complete takeover of control over the tool instance and the code defect data stored in it.

Mitigation & patch

Apply patches available from the vendor in accordance with references (GitHub Security Advisory GHSA-4v9x-cqc5-j645). Until updates are applied, it is recommended to restrict network access to the CodeChecker instance exclusively to trusted hosts and internal networks (firewall, VPN).

Who is affected

Ericsson CodeChecker in all versions up to and including 6.27.3.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:M/U:Red
  • Ericsson Codechecker

    APP
    Ericsson
    < 6.27.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-10081CRITICAL10.0PL ✓same product

Authentication bypass w Ericsson CodeChecker — pełny dostęp do API

CVE-2024-53829HIGH8.2same product

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Cla...

CVE-2024-10082HIGH8.7same product

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Cla...

CVE-2025-40843MEDIUM5.9same product

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Cla...

CVE-2025-1300MEDIUM6.1same product

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Cla...