๐Ÿ” CVE Alert

CVE-2026-52821

UNKNOWN 0.0

Kimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creation Under Unauthorized Projects

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{project} and /en/admin/project/create/{customer} require only the generic create_activity or create_project capability and do not verify edit access to the supplied Project or Customer object. A user who knows a valid project.id or customer identifier can use the preset-parent creation logic in src/Controller/ActivityController.php or src/Controller/ProjectController.php to persist a new child business object under an unauthorized parent, polluting project or customer configuration and influencing later time-entry, rate, reporting, and billing behavior. This issue is fixed in version 2.57.0.

CWE CWE-639 CWE-862
Vendor kimai
Product kimai
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for kimai kimai

Be the first to know when new unknown vulnerabilities affecting kimai kimai are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

kimai / kimai
< 2.57.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kimai/kimai/security/advisories/GHSA-3q6q-26vg-v97x github.com: https://github.com/kimai/kimai/pull/5929 github.com: https://github.com/kimai/kimai/commit/976d38e8a4485a1c923ee7b5841849e91a06e849 github.com: https://github.com/kimai/kimai/releases/tag/2.57.0 kimai.org: https://www.kimai.org/en/security/ghsa-3q6q-26vg-v97x