PT-2026-48954 · Solidtime · Solidtime

CVE-2026-47236

·

Published

2026-06-12

·

Updated

2026-06-12

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Solidtime versions prior to 0.12.2
Description An authorization bypass exists where the Jetstream web team page only verifies access using the belongsToTeam() function instead of enforcing the required invitations:view and members:view permissions. This allows any employee belonging to the organization to access pending invitation email addresses and member details through serialized Inertia props in the team page body, bypassing the restrictions imposed on the official invitations and members API.
Recommendations Update to version 0.12.2.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47236
GHSA-33XQ-WF67-C7VH

Affected Products

Solidtime