CVE-2026-25660General(ericsson / codechecker)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ericsson codechecker systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the URL ends with Authentication with certain function calls.  This bypass allows assigning arbitrary permission to any user existing in CodeChecker. This issue affects CodeChecker: through 6.27.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • codechecker

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-24); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
codechecker

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Mentions · 2026-05-05: 1Patch / Workaround · 2026-05-05: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 1Technical Details · 2026-05-05: 104-2404-2505-05
Signal classification3 categories
General
133.3%
Disclosure
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-241
General1
2026-04-251
Disclosure1
2026-05-051
Patch1
Full discourse3 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - CodeChecker authentication bypass (CVE-2026-25660) Unauthenticated users can call API endpoints to assign arbitrary permissions, leading to full privilege escalation. 👉 Update to 6.27.4+ immediately

    Post summary

    A critical authentication bypass in CodeChecker allows unauthenticated API calls to grant arbitrary permissions, leading to full privilege escalation. Users are urged to update to version 6.27.4+ immediately.

    0002093
    237 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25660 CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the URL ends… https://www.cve.org/CVERecord?id=CVE-2026-25660

    Post summary

    The entry announces an authentication bypass flaw in CodeChecker’s URL handling (CVE‑2026‑25660), but provides no evidence of exploitation or a PoC, only the basic vulnerability description.

    0000095
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-25660 Authentication Bypass in CodeChecker Through 6.27.3 Allowing Arbi... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25660 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet references CVE-2026-25660, noting an authentication bypass vulnerability in CodeChecker up to version 6.27.3, but it provides no PoC, exploit tool, active exploitation claim, or patch information.

    0000033
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appericssoncodechecker---

Explore more