Medium severity5.4NVD Advisory· Published Aug 17, 2026
CVE-2026-19966
CVE-2026-19966
Description
A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affects some unknown processing of the file /clients/save_contact of the component Contact Information Update. Such manipulation of the argument contact_id leads to authorization bypass. The attack can be launched remotely. The exploit is publicly available and might be used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=2.8
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.