Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-49992— Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes

Quick assessment

Affected
kimai kimai
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kimai 是一款开源的时间追踪应用。在 2.58.0 之前的版本中,其默认的团队创建快捷方式(涉及项目、客户和活动)存在经过身份验证的跨站请求伪造(CSRF)漏洞。这些端点通过 路由暴露,会直接创建或复用一个 ,将当前用户添加为团队负责人(teamlead),并将目标对象绑定到该团队。因此,攻击者可以诱使拥有相应权限的登录用户访问一个恶意页面,从而导致对团队、团队负责人以及对象绑定关系进行非授权变更。这是一个真实的授权结构修改问题,而不仅仅是无害的 UI 快捷方式。该漏洞已在 2.58.0 版本中得到修复。

CVSS 6.3 · Medium EPSS 0.16% · P5

Affected Version Matrix 1

VendorProduct Version RangeStatus
kimai kimai < 2.58.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-49992

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes
Source: CVE Program / CVE List V5
Vulnerability Description
Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exposed through `GET` routes and directly create or reuse a `Team`, add the current user as teamlead, and bind the target object to that team. As a result, an attacker can trick a logged-in user with the required permissions into visiting a malicious page and cause unauthorized changes to team, teamlead, and object-binding relationships. This is a real authorization-structure modification issue rather than a harmless UI shortcut. Version 2.58.0 patches the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
跨站请求伪造(CSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
kimai kimai < 2.58.0 -

II. Public POCs for CVE-2026-49992

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-49992

登录查看更多情报信息。

Vendor Advisories for CVE-2026-49992 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-49992

No comments yet


Leave a comment