CVE-2026-12620: Access Token Exposure in URL Parameters in GridTime™ 3000 GNSS Time Server
Published Jun 19, 2026
·Updated
The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints.
This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.
Affected Software
3 affected components
GridTime GridTime 3000 GNSS Time Server>=1.0r0.03<=1.1r0.0
All of the following
Microchip Gridtime 3000 Firmware>=1.0r0.03<1.2r0.0
Microchip GridTime 3000
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GridTime™ 3000 GNSS Time Serverto a version that resolves this vulnerability.Fixed in 1.2r0.0
Event History
Jun 19, 2026
CVE Published
via MITRE·03:59 PM
Data Sourced
via MITRE·03:59 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-12620?
CVE-2026-12620 has a medium severity rating of 4.6.
2
How do I fix CVE-2026-12620?
To resolve CVE-2026-12620, update the GridTime 3000 GNSS Time Server to a version beyond 1.1r0.0.
3
What impact does CVE-2026-12620 have on the GridTime 3000 GNSS Time Server?
CVE-2026-12620 can lead to exposure of access tokens through URL parameters.
4
Which versions of the GridTime 3000 GNSS Time Server are affected by CVE-2026-12620?
CVE-2026-12620 affects versions from 1.0r0.03 through 1.1r0.0 of the GridTime 3000 GNSS Time Server.
5
What type of vulnerability is CVE-2026-12620 classified as?
CVE-2026-12620 is classified as an information leak vulnerability.