CVE-2026-21694

Titra is open source project time tracking software. Versions 0.99.49 and below have Improper Access Control, allowing users to view and edit other users' time entries in private projects they have not been granted access to. This issue is fixed in version 0.99.50.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kromit:titra:*:*:*:*:*:*:*:*

History

12 Jan 2026, 18:44

Type Values Removed Values Added
First Time Kromit titra
Kromit
CPE cpe:2.3:a:kromit:titra:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References () https://github.com/kromitgmbh/titra/commit/29e6b88eca005107729e45a6f1731cf0fa5f8938 - () https://github.com/kromitgmbh/titra/commit/29e6b88eca005107729e45a6f1731cf0fa5f8938 - Patch
References () https://github.com/kromitgmbh/titra/security/advisories/GHSA-mr2r-wjf8-cj3c - () https://github.com/kromitgmbh/titra/security/advisories/GHSA-mr2r-wjf8-cj3c - Exploit, Vendor Advisory

08 Jan 2026, 20:15

Type Values Removed Values Added
References () https://github.com/kromitgmbh/titra/security/advisories/GHSA-mr2r-wjf8-cj3c - () https://github.com/kromitgmbh/titra/security/advisories/GHSA-mr2r-wjf8-cj3c -

08 Jan 2026, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-08 00:15

Updated : 2026-01-12 18:44


NVD link : CVE-2026-21694

Mitre link : CVE-2026-21694

CVE.ORG link : CVE-2026-21694


JSON object : View

Products Affected

kromit

  • titra
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo