CVE-2026-42279: CWE-639: Authorization Bypass Through User-Controlled Key in solidtime-io solidtime
CVE-2026-42279 is an authorization bypass vulnerability in solidtime version 0.12.0. The PUT API endpoint for updating time entries improperly allows a user with the time-entries:update:all permission in one organization to modify a time entry UUID belonging to another organization and rebind it to their own organization. This issue was fixed in version 0.12.1. The vulnerability has a medium severity with a CVSS score of 5.8 and does not impact confidentiality or availability but allows integrity compromise through unauthorized modification of time entries.
AI Analysis
Technical Summary
In solidtime 0.12.0, the PUT /api/v1/organizations/{organization}/time-entries/{timeEntry} endpoint accepts a timeEntry UUID from a different organization if the caller has the time-entries:update:all permission scoped to their own organization. This allows an attacker to modify a foreign time entry and associate it with objects in their own organization, bypassing intended authorization checks. The vulnerability is classified under CWE-639 (Authorization Bypass Through User-Controlled Key). It was patched in version 0.12.1.
Potential Impact
The vulnerability allows an attacker with elevated permissions in one organization to modify time entries belonging to another organization by referencing their UUIDs. This leads to unauthorized integrity modification of data across organizational boundaries. There is no impact on confidentiality or availability. No known exploits are reported in the wild.
Mitigation Recommendations
Upgrade solidtime to version 0.12.1 or later, where this authorization bypass vulnerability has been patched. Since this is an open-source product and not a cloud service, users must apply the update themselves. Patch status is confirmed by the vendor advisory stating the issue is fixed in 0.12.1.
CVE-2026-42279: CWE-639: Authorization Bypass Through User-Controlled Key in solidtime-io solidtime
Description
CVE-2026-42279 is an authorization bypass vulnerability in solidtime version 0.12.0. The PUT API endpoint for updating time entries improperly allows a user with the time-entries:update:all permission in one organization to modify a time entry UUID belonging to another organization and rebind it to their own organization. This issue was fixed in version 0.12.1. The vulnerability has a medium severity with a CVSS score of 5.8 and does not impact confidentiality or availability but allows integrity compromise through unauthorized modification of time entries.
CVSS v3.1
Score 5.8medium
Affected software
pkg:github/solidtime-io/solidtimeRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In solidtime 0.12.0, the PUT /api/v1/organizations/{organization}/time-entries/{timeEntry} endpoint accepts a timeEntry UUID from a different organization if the caller has the time-entries:update:all permission scoped to their own organization. This allows an attacker to modify a foreign time entry and associate it with objects in their own organization, bypassing intended authorization checks. The vulnerability is classified under CWE-639 (Authorization Bypass Through User-Controlled Key). It was patched in version 0.12.1.
Potential Impact
The vulnerability allows an attacker with elevated permissions in one organization to modify time entries belonging to another organization by referencing their UUIDs. This leads to unauthorized integrity modification of data across organizational boundaries. There is no impact on confidentiality or availability. No known exploits are reported in the wild.
Mitigation Recommendations
Upgrade solidtime to version 0.12.1 or later, where this authorization bypass vulnerability has been patched. Since this is an open-source product and not a cloud service, users must apply the update themselves. Patch status is confirmed by the vendor advisory stating the issue is fixed in 0.12.1.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-04-26T11:53:27.716Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 69fd6bcccbff5d8610923295
Added to database: 05/08/2026, 04:51:24 UTC
Last enriched: 05/15/2026, 11:03:47 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 137
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.