Junglewise Threat Intelligence

CVE-2026-5799: Idvlabs Ontime authorization bypass via user-controlled key

CVE-2026-5799 · Severity: high · CVSS 7.5 · Published 2026-07-07

Executive brief

Idvlabs Ontime is a software solution used for time management and scheduling. A security flaw in the system allows unauthorized individuals to bypass security checks by manipulating identification keys. This could lead to the exposure of sensitive information or unauthorized access to data within the platform.

Technical details

An authorization bypass vulnerability (CWE-639) exists in Idvlabs Ontime through version 04052026. The flaw stems from a 'User-Controlled Key' vulnerability where the application fails to properly validate that a user has the authority to access a specific resource identified by a key (such as an ID number) provided in the request. A remote, unauthenticated attacker can exploit this by modifying these identifiers in network requests to access data belonging to other users or the system. The vulnerability has a CVSS 3.1 base score of 7.5, reflecting high confidentiality impact with no requirement for privileges or user interaction.

Affected products

  • Idvlabs Software and Consulting Services Inc. Ontime through 04052026

Timeline

  • 2026-07-07: advisory: NVD publication date
  • 2026-07-07: disclosed: TR-CERT advisory published

References

Related threats