Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-52819— Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the target

Quick assessment

Affected
kimai kimai
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kimai 是一款开源的时间追踪应用程序。在 2.57.0 版本之前,GET /api/timesheets 列表端点允许拥有 权限的调用者通过 和 参数指定目标用户,但未对请求者是否通过 权限或确认该请求者(具有 ROLE_TEAMLEAD 角色)是否领导了包含每个目标用户的团队进行验证。 具体而言, 将解析后的用户直接添加到查询条件中,而项目和客户过滤仍然允许访问未加范围限制的项目或仅具有普通团队成员资格的项目中的记录。这导致团队负责人(teamlead)能够获取其他用户的描述信息、时间数据、标签、费率(rat

CVSS 6.3 · Medium

Possible ATT&CK Techniques 2 AI

T1078 · Valid Accounts T1023
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-52819

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the target
Source: CVE Program / CVE List V5
Vulnerability Description
Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user and users[] target identifiers from a caller with view_other_timesheet but does not apply access_user or verify that a ROLE_TEAMLEAD requester leads a team containing each target user. TimesheetController::cgetAction() adds the resolved users directly to the query while project and customer filtering still permits records on unscoped projects or projects sharing ordinary team membership, allowing a teamlead to retrieve another user's descriptions, timing data, tags, rate, and internalRate even though GET /api/timesheets/{id} would deny access through TimesheetVoter. This issue is fixed in version 2.57.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
kimai kimai < 2.57.0 -

II. Public POCs for CVE-2026-52819

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-52819

登录查看更多情报信息。

Patches & Fixes for CVE-2026-52819 (1)

Vendor Advisories for CVE-2026-52819 (2)

Vendor Pages for CVE-2026-52819 (1)

Same Patch Batch · kimai · 2026-09-15 · 10 CVEs total

CVE-2026-52824 9.1 CRITICAL Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover
CVE-2026-52827 7.1 HIGH Kimai: Two-factor authentication bypass on the Kimai API
CVE-2026-52825 5.3 MEDIUM Kimai: Improper Authorization in Kimai Team Member and Team Activity Assignment APIs Allow
CVE-2026-52820 5.3 MEDIUM Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_buil
CVE-2026-52823 5.3 MEDIUM Kimai: Login CSRF in Kimai Timesheet Stop and Restart API Endpoints Allows Unauthorized St
CVE-2026-52821 5.3 MEDIUM Kimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creati
CVE-2026-52826 5.3 MEDIUM Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints
CVE-2026-52828 5.3 MEDIUM Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access
CVE-2026-52822 5.3 MEDIUM Kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timeshee

IV. Related Vulnerabilities

V. Comments for CVE-2026-52819

No comments yet


Leave a comment