← Vulnerability feed

Vulnerability record · CVE-2026-21695 · published 8 January 2026

CVE-2026-21695: Kromit titra mass assignment vulnerability

KKromit · Titra

Titra is open source project time tracking software. In versions 0.99.49 and below, an API has a Mass Assignment vulnerability which allows authenticated users to inject arbitrary fields into time entries, bypassing business logic controls via the customfields parameter. The affected endpoint uses the JavaScript spread operator (...customfields) to merge user-controlled input directly into the database document. While customfields is validated as an Object type, there is no validation of which keys are permitted inside that object. This allows attackers to overwrite protected fields such as userId, hours, and state. The issue is fixed in version 0.99.50.

4.3 CVSS 3.1 Medium EPSS 0.28% · top 81.3% CWE-915 · Mass assignment
4.3CVSS 3.1 base score
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Titra is open source project time tracking software. In versions 0.99.49 and below, an API has a Mass Assignment vulnerability which allows authenticated users to inject arbitrary fields into time entries, bypassing business logic controls via the customfields parameter. The affected endpoint uses the JavaScript spread operator (...customfields) to merge user-controlled input directly into the database document. While customfields is validated as an Object type, there is no validation of which keys are permitted inside that object. This allows attackers to overwrite protected fields such as userId, hours, and state. The issue is fixed in version 0.99.50.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-21695 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2022-2595Kromit titra improper authorization vulnerabilityImproper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.EPSS 1.3%9.8CVE-2022-2098Kromit titra weak password requirements vulnerabilityWeak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.EPSS 1.0%9.1CVE-2025-69288Kromit titra improper input validation vulnerabilityTitra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule …EPSS 0.85%8.1CVE-2026-21694Kromit titra improper access control vulnerabilityTitra is open source project time tracking software. Versions 0.99.49 and below have Improper Access Control, allowing users to view and edit other u…EPSS 0.28%8.0CVE-2022-2027Kromit titra csv injection vulnerabilityImproper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.EPSS 1.2%5.4CVE-2022-2026Kromit titra cross-site scripting vulnerabilityCross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0.EPSS 0.71%5.4CVE-2022-2028Kromit titra cross-site scripting vulnerabilityCross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0.EPSS 0.71%5.4CVE-2022-2029Kromit titra cross-site scripting vulnerabilityCross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0.EPSS 0.71%

Source: NIST National Vulnerability Database (record CVE-2026-21695), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.