Impact
The vulnerability is an authorization bypass that allows an attacker to supply a user‑controlled key to override trusted identifiers in Idvlabs’ Ontime product. By doing so, the attacker can gain unauthorized access to protected functionality that should otherwise be restricted to authenticated users, effectively acquiring the same privileges as a legitimate user or higher. This flaw is a classic instance of an Insecure Direct Object Reference (CWE‑639) that occurs when the application accepts an identifier without verifying that the requesting user is authorized for the requested resource.
Affected Systems
Idvlabs Software and Consulting Services Inc. publishes the Ontime application. Versions of Ontime up to and including 04052026 are affected by this IDOR vulnerability. Any deployment of Ontime that uses the pre‑04052026 code base is susceptible.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity impact. The EPSS score is below 1 %, suggesting a very low modelled likelihood of exploitation at this time. The vulnerability is currently not listed in CISA’s KEV catalog, implying no known large‑scale exploitation. Based on the description, the likely attack path involves supplying a forged keyword to a web endpoint or API that processes trusted identifiers, although the advisory does not specify the exact vector. The absence from KEV does not preclude a targeted exploit.
OpenCVE Enrichment