PT-2026-56161 · Ontime · Ontime
CVE-2026-5799
·
Published
2026-07-07
·
Updated
2026-07-07
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ontime versions prior to 04052026
Description
An authorization bypass exists due to a user-controlled key vulnerability that allows the exploitation of trusted identifiers. This issue enables an Insecure Direct Object Reference (IDOR), where a user can access or modify data that does not belong to them by manipulating a key used for identification.
Recommendations
Update Ontime to a version released after 04052026.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ontime