Authenticated Cross-Site Request Forgery in Kimai Time Tracking Application
CVE-2026-49992
6.3MEDIUM
What is CVE-2026-49992?
The Kimai open-source time tracking application is susceptible to authenticated cross-site request forgery issues in its default team creation shortcuts. Versions prior to 2.58.0 expose specific endpoints via GET requests, allowing an attacker to deceive a logged-in user with the correct permissions into accessing a malicious URL. This can lead to unauthorized modifications in team relationships, designating the current user as a team lead, and manipulating bindings with various project objects. This vulnerability compromises the integrity of the application's authorization model. The issue has been resolved in version 2.58.0.
Affected Version(s)
kimai < 2.58.0
