Description
Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted Identifiers.

This issue affects Ontime: through 04052026.
Published: 2026-07-07
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Idvlabs Ontime software contains an identity-based authorization bypass vulnerability where user-controlled keys are improperly trusted. This flaw, classified as CWE-639, allows an authenticated user to manipulate the trusted identifier field and gain unauthorized access to other users’ records, effectively performing an IDOR attack and escalating privileges.

Affected Systems

Ontime versions up to 04052026 are affected. The product is distributed by Idvlabs Software and Consulting Services Inc. No patch versions are listed in the data; administrators should verify that their deployment is beyond 04052026.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity vulnerability. Expl Ontime API where a user-provided key is accepted without proper validation. The EPSS score of < 1% indicates a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog, suggesting no known active exploitation yet. However, the potential for unauthorized data access warrants prompt remediation.

Generated by OpenCVE AI on July 26, 2026 at 19:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Ontime to a version newer than 04052026
  • Implement strict validation on trusted identifier inputs to reject uncontrolled keys
  • Enforce least-privilege access controls and monitor for anomalous read or modification attempts

Generated by OpenCVE AI on July 26, 2026 at 19:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Idvlabs
Idvlabs ontime
Vendors & Products Idvlabs
Idvlabs ontime

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Description Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted Identifiers. This issue affects Ontime: through 04052026.
Title IDOR in Idvlabs' Ontime
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-07T13:26:51.694Z

Reserved: 2026-04-08T14:17:21.176Z

Link: CVE-2026-5799

cve-icon Vulnrichment

Updated: 2026-07-07T13:26:47.857Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:45:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key