Impact
Its authorization bypass flaw permits an attacker to override Trusted Identifiers by supplying a user‑controlled key, thereby gaining access to protected functionality that should be restricted. This gives the attacker the same privileges as an authenticated user or higher, enabling compromised data or actions. The weakness is an IDOR (CWE-639) flaw that occurs when the application trusts the key without verifying that the requesting user is authorized.
Affected Systems
Idvlabs Software and Consulting Services Inc. releases a product entitled Ontime. Versions up to and including 04052026 are affected by this IDOR. The vulnerability exists in the version's trusted‑identifier handling module and is present in any deployment of Ontime prior to the release that incorporates this module's logic.
Risk and Exploitability
Security analysts rate the vulnerability with a CVSS score of 7.5, indicating a high severity. The EPSS score is below 1 %, showing a very low modelled chance of exploitation at this time, and the vulnerability is not yet catalogued in CISA’s KEV list. Based on the description, the likely attack path involves supplying a forged key to a web endpoint or API that processes trusted identifiers, but the exact vector is not explicitly stated in the advisory; it is inferred that the exploit is achievable through remote access to the affected application. The absence from KEV suggests no known large‑scale attacks but does not preclude a targeted exploit.
OpenCVE Enrichment