SB2026092293 - Multiple vulnerabilities in titra
Published: September 22, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Protection mechanism failure (CVE-ID: N/A)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code on the host system.
The vulnerability exists due to protection mechanism failure in validateSandboxCode in vm_sandbox.js when executing stored sandbox scripts. A remote privileged user can submit a crafted sandbox script to execute arbitrary code on the host system.
The script execution context exposes host-realm objects and permits access to built-in modules.
2) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in the inboundinterfaces and outboundinterfaces publications when handling subscription requests. A remote attacker can subscribe to the affected publications to disclose sensitive information.
Published documents include the processData server-side integration script.
3) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to delete other users' project time entries.
The vulnerability exists due to missing authorization in the deleteTimeCardsForWeek DDP method when processing timecard deletion requests. A remote user can invoke the method with a matching project, task, and date range to delete other users' time entries.
Exploitation requires another user's entries to match the specified project, task, and date range.
Remediation
Install update from vendor's website.