๐Ÿ” CVE Alert

CVE-2026-52828

UNKNOWN 0.0

Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportController::editExportTemplate() inherit only the class-level create_export permission, which ROLE_TEAMLEAD receives by default, and omit the create_export_template permission required by the API routes and user interface. A teamlead can directly access the export template creation and editing web routes to create or modify global ExportTemplate records marked available to all users, altering export columns, renderer, format, and output used by other users and administrators. This issue is fixed in version 2.58.0.

CWE CWE-862
Vendor kimai
Product kimai
Published Sep 15, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for kimai kimai

Be the first to know when new unknown vulnerabilities affecting kimai kimai are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

kimai / kimai
< 2.58.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kimai/kimai/security/advisories/GHSA-rw46-qg69-vg6h github.com: https://github.com/kimai/kimai/pull/5952 github.com: https://github.com/kimai/kimai/commit/31a8f887a5cda517db7b4320a7ad997c87d08601 github.com: https://github.com/kimai/kimai/releases/tag/2.58.0 kimai.org: https://www.kimai.org/en/security/ghsa-rw46-qg69-vg6h