Junglewise Threat Intelligence

CVE-2026-12620: Microchip GridTime 3000 access token exposure in URL parameters

CVE-2026-12620 · Severity: info · CVSS 4.6 · Published 2026-06-19

Technologies: Microchip Technology GridTime 3000 GNSS Time Server. Vendors: Microchip Technology.

Executive brief

The GridTime 3000 GNSS Time Server, used for precise synchronization in critical infrastructure, contains a security flaw where sensitive access tokens are exposed in web addresses. This could allow an unauthorized person with access to network logs or browser history to obtain these tokens and potentially gain unauthorized access to the device management interface. Such access could disrupt time synchronization services or allow for unauthorized configuration changes.

Technical details

The GridTime 3000 GNSS Time Server is vulnerable to information exposure (CWE-200) because it transmits session access tokens as plaintext URL parameters rather than using secure headers or request bodies. An attacker with access to network traffic logs, proxy server logs, or browser history could intercept these tokens. While the CVSS score suggests high privileges are required for the initial session, the exposure of the token allows for session hijacking or subsequent unauthorized actions. The vulnerability exists in versions 1.0r0.03 through 1.1r0.0.

Affected products

  • Microchip Technology GridTime 3000 GNSS Time Server 1.0r0.03 through 1.1r0.0

Timeline

  • 2026-06-19: disclosed: Initial advisory publication by Microchip Technology

References

Related threats