CVE-2026-21694

MEDIUM

Kromit Titra < 0.99.50 - Improper Access Control

Title source: rule
STIX 2.1

Description

Titra is open source project time tracking software. Versions 0.99.49 and below have Improper Access Control, allowing users to view and edit other users' time entries in private projects they have not been granted access to. This issue is fixed in version 0.99.50.

Scores

CVSS v3 6.8
EPSS 0.0004
EPSS Percentile 13.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
kromit/titra < 0.99.50
Published Jan 08, 2026
Tracked Since Feb 18, 2026