File Inclusion Vulnerability in Kimai Time Tracking Application
CVE-2026-44298

4.1MEDIUM

Key Information:

Vendor

Kimai

Status
Vendor
CVE Published:
8 May 2026

What is CVE-2026-44298?

The Kimai time tracking application allows users with the System-Admin role and specific permissions to upload customized PDF invoice templates. A vulnerability exists where uploaded files can be manipulated to trigger the loading of arbitrary files from the server. During the rendering of the PDF, the application leverages the mPDF library, which can expose sensitive data that the PHP worker can access. This issue has been resolved in version 2.56.0, ensuring that such unauthorized file inclusions are no longer possible.

Affected Version(s)

kimai >= 2.32.0, < 2.56.0

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.