Authentication Bypass in Kimai Open-Source Time Tracking Application
CVE-2026-52819
6.3MEDIUM
What is CVE-2026-52819?
The Kimai time tracking application has a vulnerability that allows unauthorized users to access sensitive information. Prior to version 2.57.0, the API endpoint for listing timesheets did not adequately enforce access controls. Users with the 'view_other_timesheet' permission could bypass role checks to access data belonging to other users. This included sensitive information such as descriptions, timing data, tags, rates, and internal rates. This security issue was addressed in version 2.57.0, which implements proper verification before allowing access to another user's timesheet data.
Affected Version(s)
kimai < 2.57.0
