Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-52820— Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypass

Quick assessment

Affected
kimai kimai
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kimai 是一款开源的时间跟踪应用程序。在 2.57.0 版本之前, 和 接口通过 和 接受用户可控的项目标识符,而 方法将该标识符置于一个无条件的 OR 分支中,从而绕过了团队访问权限的控制条件。因此,任何拥有 权限的已认证用户可以将自己所有的工时记录关联到不属于其所属团队的项目,从而持久化保存未授权的项目归属信息,并可通过 检索项目和客户元数据。 现在会检查被修改的项目和活动关联是否符合当前团队的访问权限。该问题已在 2.57.0 版本中修复。

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-52820

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypass
Source: CVE Program / CVE List V5
Vulnerability Description
Kimai is an open-source time tracking application. Prior to 2.57.0, PATCH /api/timesheets/{id} and POST /api/timesheets accept a user-controlled project identifier through TimesheetApiEditForm and FormTrait, and ProjectRepository::getQueryBuilderForFormType() places that identifier in an unconditional OR branch that bypasses the team access criteria. Any authenticated user with edit_own_timesheet can therefore assign an owned timesheet to a project outside the user's teams, persist unauthorized project attribution, and retrieve project and customer metadata through GET /api/timesheets/{id}?full=true. TimesheetTeamAccessValidator now checks changed project and activity associations against current team access. This issue is fixed in version 2.57.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
kimai kimai < 2.57.0 -

II. Public POCs for CVE-2026-52820

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-52820

登录查看更多情报信息。

Patches & Fixes for CVE-2026-52820 (1)

Vendor Advisories for CVE-2026-52820 (2)

Vendor Pages for CVE-2026-52820 (1)

Same Patch Batch · kimai · 2026-09-15 · 10 CVEs total

CVE-2026-52824 9.1 CRITICAL Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover
CVE-2026-52827 7.1 HIGH Kimai: Two-factor authentication bypass on the Kimai API
CVE-2026-52819 6.3 MEDIUM Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' ti
CVE-2026-52825 5.3 MEDIUM Kimai: Improper Authorization in Kimai Team Member and Team Activity Assignment APIs Allow
CVE-2026-52823 5.3 MEDIUM Kimai: Login CSRF in Kimai Timesheet Stop and Restart API Endpoints Allows Unauthorized St
CVE-2026-52821 5.3 MEDIUM Kimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creati
CVE-2026-52826 5.3 MEDIUM Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints
CVE-2026-52828 5.3 MEDIUM Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access
CVE-2026-52822 5.3 MEDIUM Kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timeshee

IV. Related Vulnerabilities

V. Comments for CVE-2026-52820

No comments yet


Leave a comment