Impact
Idvlabs Ontime software contains an identity-based authorization bypass vulnerability where user-controlled keys are improperly trusted. This flaw, classified as CWE-639, allows an authenticated user to manipulate the trusted identifier field and gain unauthorized access to other users’ records, effectively performing an IDOR attack and escalating privileges.
Affected Systems
Ontime versions up to 04052026 are affected. The product is distributed by Idvlabs Software and Consulting Services Inc. No patch versions are listed in the data; administrators should verify that their deployment is beyond 04052026.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability. Expl Ontime API where a user-provided key is accepted without proper validation. The EPSS score of < 1% indicates a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog, suggesting no known active exploitation yet. However, the potential for unauthorized data access warrants prompt remediation.
OpenCVE Enrichment