What is CVE-2026-19966?
A vulnerability was found in CodeCanyon TimeCamp Integration for CRM up to version 2.8, affecting the `/clients/save_contact` file where the `contact_id` argument allows authorization bypass. This could let an attacker update contact information without proper permissions. Users are advised to update the module immediately.
Azərbaycanca: CodeCanyon TimeCamp Integration for CRM modulunda 2.8 versiyasına qədər təsir edən, `/clients/save_contact` faylındaki `contact_id` argumenti vasitəsilə avtorizasiya yan keçməyə səbəb olan zəiflik aşkar edilib. Bu, hücumçuya əlaqə məlumatlarını yeniləmək üçün tələb olunan icazəni keçməyə imkan verir. İstifadəçilərə dərhal modulu ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ1
Which function is affected by the CVE-2026-19966 vulnerability in the CodeCanyon TimeCamp Integration for CRM module?
The vulnerability affects the `contact_id` argument in the `/clients/save_contact` file. This leads to an authorization bypass, allowing an attacker to update contact information without the required permissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.