Executive brief
Idvlabs Ontime, a software solution for business management, contains a security flaw that allows unauthorized access to sensitive information. By manipulating specific identifiers used by the system, an attacker can bypass security checks to view data they are not permitted to see. This could lead to the exposure of confidential business records or customer information without requiring any user interaction or special login credentials.
Technical details
An authorization bypass vulnerability (CWE-639) exists in Idvlabs Ontime through version 04052026. The flaw stems from the application's reliance on user-controlled keys or identifiers to perform authorization checks. A remote, unauthenticated attacker can exploit this by providing manipulated identifiers (Insecure Direct Object Reference) to access resources or data belonging to other users or the system. The vulnerability is exploitable over the network with low complexity and requires no user interaction, potentially leading to high confidentiality impact.
Affected products
- Idvlabs Software and Consulting Services Inc. Ontime through 04052026
Timeline
- 2026-07-07: advisory: Published by NVD and TR-CERT