solidtime is an open-source time-tracking app. Prior to version 0.11.6, the project detail endpoint GET /api/v1/organizations/{org}/projects/{project} allows any authenticated Employee to access any project in the organization by UUID, including private projects they are not a member of. The index() endpoint correctly applies the visibleByEmployee() scope, but show() does not. This issue has been patched in version 0.11.6.
History

Tue, 24 Mar 2026 19:45:00 +0000

Type Values Removed Values Added
Description solidtime is an open-source time-tracking app. Prior to version 0.11.6, the project detail endpoint GET /api/v1/organizations/{org}/projects/{project} allows any authenticated Employee to access any project in the organization by UUID, including private projects they are not a member of. The index() endpoint correctly applies the visibleByEmployee() scope, but show() does not. This issue has been patched in version 0.11.6.
Title solidtime vulnerable to IDOR in private projects
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-24T19:30:27.471Z

Reserved: 2026-03-18T22:15:11.813Z

Link: CVE-2026-33345

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-24T20:16:29.073

Modified: 2026-03-24T20:16:29.073

Link: CVE-2026-33345

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.