SB2026092293 - Multiple vulnerabilities in titra



SB2026092293 - Multiple vulnerabilities in titra

Published: September 22, 2026

Security Bulletin ID SB2026092293
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 33% Low 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Protection mechanism failure (CVE-ID: N/A)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code on the host system.

The vulnerability exists due to protection mechanism failure in validateSandboxCode in vm_sandbox.js when executing stored sandbox scripts. A remote privileged user can submit a crafted sandbox script to execute arbitrary code on the host system.

The script execution context exposes host-realm objects and permits access to built-in modules.


2) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to missing authorization in the inboundinterfaces and outboundinterfaces publications when handling subscription requests. A remote attacker can subscribe to the affected publications to disclose sensitive information.

Published documents include the processData server-side integration script.


3) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to delete other users' project time entries.

The vulnerability exists due to missing authorization in the deleteTimeCardsForWeek DDP method when processing timecard deletion requests. A remote user can invoke the method with a matching project, task, and date range to delete other users' time entries.

Exploitation requires another user's entries to match the specified project, task, and date range.


Remediation

Install update from vendor's website.