Description
Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted Identifiers.

This issue affects Ontime: through 04052026.
Published: 2026-07-07
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authorization bypass that allows an attacker to supply a user‑controlled key to override trusted identifiers in Idvlabs’ Ontime product. By doing so, the attacker can gain unauthorized access to protected functionality that should otherwise be restricted to authenticated users, effectively acquiring the same privileges as a legitimate user or higher. This flaw is a classic instance of an Insecure Direct Object Reference (CWE‑639) that occurs when the application accepts an identifier without verifying that the requesting user is authorized for the requested resource.

Affected Systems

Idvlabs Software and Consulting Services Inc. publishes the Ontime application. Versions of Ontime up to and including 04052026 are affected by this IDOR vulnerability. Any deployment of Ontime that uses the pre‑04052026 code base is susceptible.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity impact. The EPSS score is below 1 %, suggesting a very low modelled likelihood of exploitation at this time. The vulnerability is currently not listed in CISA’s KEV catalog, implying no known large‑scale exploitation. Based on the description, the likely attack path involves supplying a forged keyword to a web endpoint or API that processes trusted identifiers, although the advisory does not specify the exact vector. The absence from KEV does not preclude a targeted exploit.

Generated by OpenCVE AI on August 1, 2026 at 17:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch for Ontime issued after version 04052026.
  • Disable or restrict use of user‑controlled keys for trusted identifiers until a fix is applied.
  • Enforce strict authorization checks before allowing any operation that relies on trusted identifiers.

Generated by OpenCVE AI on August 1, 2026 at 17:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Idvlabs
Idvlabs ontime
Vendors & Products Idvlabs
Idvlabs ontime

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Description Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted Identifiers. This issue affects Ontime: through 04052026.
Title IDOR in Idvlabs' Ontime
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-07T13:25:37.426Z

Reserved: 2026-04-07T12:08:28.185Z

Link: CVE-2026-5730

cve-icon Vulnrichment

Updated: 2026-07-07T13:25:30.915Z

cve-icon NVD

Status : Deferred

Published: 2026-07-07T08:16:25.540

Modified: 2026-07-07T14:16:34.343

Link: CVE-2026-5730

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T17:45:04Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key