File Inclusion Vulnerability in Kimai Time Tracking Application
CVE-2026-44298
4.1MEDIUM
What is CVE-2026-44298?
The Kimai time tracking application allows users with the System-Admin role and specific permissions to upload customized PDF invoice templates. A vulnerability exists where uploaded files can be manipulated to trigger the loading of arbitrary files from the server. During the rendering of the PDF, the application leverages the mPDF library, which can expose sensitive data that the PHP worker can access. This issue has been resolved in version 2.56.0, ensuring that such unauthorized file inclusions are no longer possible.
Affected Version(s)
kimai >= 2.32.0, < 2.56.0
