Authorization Flaw in Kimai Time Tracking Application
CVE-2026-52822

5.3MEDIUM

Key Information:

Vendor

Kimai

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-52822?

An authorization flaw in the Kimai time tracking application allows users to create new time records from historical timesheets, even after their access to specific projects or activities has been revoked. This vulnerability affects the evaluation of user permissions during operations like restarting or duplicating timesheets. The system's logic does not properly verify current team access against referenced projects, leading to potential misuse that can distort budgets, statistical reports, and invoices. This issue has been resolved in version 2.58.0.

Affected Version(s)

kimai < 2.58.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.