CVE-2026-42092
Last modified
CVE-2026-42092 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all global settings without any admin or role check. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all global settings without any admin or role check. Any authenticated user can subscribe via DDP and receive sensitive configuration fields such as google_secret, openai_apikey, and google_clientid. At time of publication no public patch is available.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-42092?
How severe is CVE-2026-42092?
How do I fix CVE-2026-42092?
Are you affected by CVE-2026-42092?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
