Authentication Bypass in Kimai Open-Source Time Tracking Application
CVE-2026-52819

6.3MEDIUM

Key Information:

Vendor

Kimai

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-52819?

The Kimai time tracking application has a vulnerability that allows unauthorized users to access sensitive information. Prior to version 2.57.0, the API endpoint for listing timesheets did not adequately enforce access controls. Users with the 'view_other_timesheet' permission could bypass role checks to access data belonging to other users. This included sensitive information such as descriptions, timing data, tags, rates, and internal rates. This security issue was addressed in version 2.57.0, which implements proper verification before allowing access to another user's timesheet data.

Affected Version(s)

kimai < 2.57.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.