CVE List

CVE-2025-15563

Moderate 5.3

Any unauthenticated user can reset the WorkTime on-prem database configuration by sending a specific HTTP request to the WorkTime server. No authorization check is applied here.

Published February 19, 2026.

Affected software

Get alerts for Nestersoft Worktime

Reference links