Authorization Flaw in Kimai Time Tracking Application
CVE-2026-52822
5.3MEDIUM
What is CVE-2026-52822?
An authorization flaw in the Kimai time tracking application allows users to create new time records from historical timesheets, even after their access to specific projects or activities has been revoked. This vulnerability affects the evaluation of user permissions during operations like restarting or duplicating timesheets. The system's logic does not properly verify current team access against referenced projects, leading to potential misuse that can distort budgets, statistical reports, and invoices. This issue has been resolved in version 2.58.0.
Affected Version(s)
kimai < 2.58.0
