Microchip TimePictra Missing Authentication Vulnerability in Web Application Allowing Unauthenticated Access to Critical Functions

Vulnerability

A vulnerability in the Microchip TimePictra web application, affecting versions 11.0 through 11.3 SP2, allows missing authentication for critical functions. This issue enables unauthorized access to endpoints for creating and deleting network elements, potentially leading to unauthorized manipulation of network configurations.

Impact

Exploitation of this vulnerability could allow an attacker to create or delete tracked network elements within the TimePictra application.

Remediation

It is recommended to control access to the TimePictra web application. Microchip plans to address this vulnerability in a future release.

Added: Feb 28, 2026, 12:18 PM
Updated: Feb 28, 2026, 12:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
3.3
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.