← Vulnerability feed

Vulnerability record · CVE-2026-21694 · published 8 January 2026

CVE-2026-21694: Kromit titra improper access control vulnerability

KKromit · Titra

Titra is open source project time tracking software. Versions 0.99.49 and below have Improper Access Control, allowing users to view and edit other users' time entries in private projects they have not been granted access to. This issue is fixed in version 0.99.50.

8.1 CVSS 3.1 High EPSS 0.28% · top 81.8% CWE-284 · Improper access control
8.1CVSS 3.1 base score
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Titra is open source project time tracking software. Versions 0.99.49 and below have Improper Access Control, allowing users to view and edit other users' time entries in private projects they have not been granted access to. This issue is fixed in version 0.99.50.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-21694 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2022-2595Kromit titra improper authorization vulnerabilityImproper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.EPSS 1.3%9.8CVE-2022-2098Kromit titra weak password requirements vulnerabilityWeak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.EPSS 1.0%9.1CVE-2025-69288Kromit titra improper input validation vulnerabilityTitra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule …EPSS 0.85%8.0CVE-2022-2027Kromit titra csv injection vulnerabilityImproper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.EPSS 1.2%5.4CVE-2022-2026Kromit titra cross-site scripting vulnerabilityCross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0.EPSS 0.71%5.4CVE-2022-2028Kromit titra cross-site scripting vulnerabilityCross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0.EPSS 0.71%5.4CVE-2022-2029Kromit titra cross-site scripting vulnerabilityCross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0.EPSS 0.71%4.3CVE-2026-21695Kromit titra mass assignment vulnerabilityTitra is open source project time tracking software. In versions 0.99.49 and below, an API has a Mass Assignment vulnerability which allows authentic…EPSS 0.28%

Source: NIST National Vulnerability Database (record CVE-2026-21694), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.