PT-2026-48954 · Solidtime · Solidtime
CVE-2026-47236
·
Published
2026-06-12
·
Updated
2026-06-12
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Solidtime versions prior to 0.12.2
Description
An authorization bypass exists where the Jetstream web team page only verifies access using the
belongsToTeam() function instead of enforcing the required invitations:view and members:view permissions. This allows any employee belonging to the organization to access pending invitation email addresses and member details through serialized Inertia props in the team page body, bypassing the restrictions imposed on the official invitations and members API.Recommendations
Update to version 0.12.2.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Solidtime