๐Ÿ” CVE Alert

CVE-2026-52826

UNKNOWN 0.0

Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate Manipulation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/{rate}, /en/admin/customer/{id}/rate/{rate}, and /en/admin/activity/{id}/rate/{rate} independently resolve the authorized parent identifier and the attacker-selected child rate identifier without confirming that the ProjectRate, CustomerRate, or ActivityRate belongs to that parent. An authenticated user who can edit one parent object can pair it with a rate record from an unauthorized project, customer, or activity and persist changes to billing configuration in kimai2_projects_rates, kimai2_customers_rates, or kimai2_activities_rates. This issue is fixed in version 2.57.0.

CWE CWE-285 CWE-639
Vendor kimai
Product kimai
Published Sep 15, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for kimai kimai

Be the first to know when new unknown vulnerabilities affecting kimai kimai are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

kimai / kimai
< 2.57.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kimai/kimai/security/advisories/GHSA-2xgg-2x8h-8xw4 github.com: https://github.com/kimai/kimai/pull/5929 github.com: https://github.com/kimai/kimai/commit/976d38e8a4485a1c923ee7b5841849e91a06e849 github.com: https://github.com/kimai/kimai/releases/tag/2.57.0 kimai.org: https://www.kimai.org/en/security/ghsa-2xgg-2x8h-8xw4