Description
Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted Identifiers.

This issue affects Ontime: through 04052026.
Published: 2026-07-07
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Its authorization bypass flaw permits an attacker to override Trusted Identifiers by supplying a user‑controlled key, thereby gaining access to protected functionality that should be restricted. This gives the attacker the same privileges as an authenticated user or higher, enabling compromised data or actions. The weakness is an IDOR (CWE-639) flaw that occurs when the application trusts the key without verifying that the requesting user is authorized.

Affected Systems

Idvlabs Software and Consulting Services Inc. releases a product entitled Ontime. Versions up to and including 04052026 are affected by this IDOR. The vulnerability exists in the version's trusted‑identifier handling module and is present in any deployment of Ontime prior to the release that incorporates this module's logic.

Risk and Exploitability

Security analysts rate the vulnerability with a CVSS score of 7.5, indicating a high severity. The EPSS score is below 1 %, showing a very low modelled chance of exploitation at this time, and the vulnerability is not yet catalogued in CISA’s KEV list. Based on the description, the likely attack path involves supplying a forged key to a web endpoint or API that processes trusted identifiers, but the exact vector is not explicitly stated in the advisory; it is inferred that the exploit is achievable through remote access to the affected application. The absence from KEV suggests no known large‑scale attacks but does not preclude a targeted exploit.

Generated by OpenCVE AI on July 23, 2026 at 13:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch for Ontime issued after version 04052026.
  • Disable or restrict use of user‑controlled keys for trusted identifiers until a fix is applied.
  • Enforce strict authorization checks before allowing any operation that relies on trusted identifiers.

Generated by OpenCVE AI on July 23, 2026 at 13:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Idvlabs
Idvlabs ontime
Vendors & Products Idvlabs
Idvlabs ontime

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Description Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted Identifiers. This issue affects Ontime: through 04052026.
Title IDOR in Idvlabs' Ontime
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-07T13:25:37.426Z

Reserved: 2026-04-07T12:08:28.185Z

Link: CVE-2026-5730

cve-icon Vulnrichment

Updated: 2026-07-07T13:25:30.915Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T14:00:07Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key