PT-2026-38663 · Solidtime · Solidtime

Pyuysig

·

Published

2026-05-08

·

Updated

2026-05-09

·

CVE-2026-42279

CVSS v3.1

5.8

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions solidtime version 0.12.0
Description An issue exists where the 'PUT /api/v1/organizations/{organization}/time-entries/{timeEntry}' API accepts a route-bound timeEntry from a different organization. This occurs when the caller possesses the time-entries:update:all permission within the organization specified in the URL, enabling a known foreign time-entry UUID to be modified and rebound to objects within the caller's own organization.
Recommendations Update to version 0.12.1.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-42279

Affected Products

Solidtime