Junglewise Threat Intelligence

CVE-2026-19966: CodeCanyon TimeCamp Integration authorization bypass in contact update

CVE-2026-19966 · Severity: medium · CVSS 5.4 · Published 2026-08-17

Executive brief

TimeCamp Integration for CRM is a plugin that manages contact and customer information within RISE CRM. A flaw in the contact update endpoint allows authenticated users to modify other users' contact records by manipulating object identifiers, potentially leading to unauthorized changes to customer data, privacy violations, and account compromise.

Technical details

The vulnerability is an insecure direct object reference (IDOR) in the POST /clients/save_contact/ endpoint. The component accepts a user-controlled contact_id parameter to identify which record to update but fails to enforce authorization checks to verify the authenticated user owns or has permission to modify that contact. An authenticated attacker can change the contact_id value to target other users' records and modify personal information including name, email, phone, and job title. The attack requires valid authentication and network access to the endpoint. No patch information is currently available.

Affected products

  • CodeCanyon TimeCamp Integration for RISE CRM up to 2.8

Timeline

  • 2026-06-29: disclosed: Vulnerability disclosed on GitHub
  • 2026-08-17: advisory: CVE-2026-19966 published

References