PSIRT-145: GridTime™ 3000 GNSS Time Server Access Token Exposure
Vulnerability Details
Access Token Exposure in URL Parameters in GridTime™ 3000 GNSS Time Server
Several endpoints leaked the access token when accessed in the GridTime 3000 GNSS Time Server. This issue affects GridTime 3000: from 1.0r0.03 before 1.2r0.0.
Date of Disclosure: 06/10/2026
Affected Product:GridTime 3000 GNSS Time Server
Vulnerability Type: Access token exposure
CVE Identifier: CVE-2026-145
CVSS Score: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:A
CVSS 4.0 Score: 4.6 / Medium
Vulnerability Description:
The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints
{"SalesForceSecurePath":"https://microchip.my.salesforce-scrt.com","EmbeddedServiceName":"Messaging_For_Microchip","SalesForcePath":"https://microchip.my.site.com/ESWMessagingForMicrochi1755319480924","AgentAvailableHeader":"No problem. Chat with our engineering experts or schedule a call that's convenient for you.","ScheduleCallUrl":"https://microchip.my.site.com/schedulemeetingportal/s/","SalesforceOrgId":"00Do0000000KAkK","JsUrl":"https://microchip.my.site.com/ESWMessagingForMicrochi1755319480924/assets/js/bootstrap.min.js"}