Access Control Vulnerability in Kimai Open Source Time Tracking Application
CVE-2026-52828

5.3MEDIUM

Key Information:

Vendor

Kimai

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-52828?

An access control vulnerability in Kimai, prior to version 2.58.0, has been identified in the ExportController functions, where insufficient permissions allow users with the ROLE_TEAMLEAD to create and modify global ExportTemplate records. This results in potential alterations to export columns, renderer, format, and output utilized by all users, including administrators. This can lead to unauthorized data exposure and manipulation. Users are encouraged to upgrade to version 2.58.0 or later to mitigate this issue.

Affected Version(s)

kimai < 2.58.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.