Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-52821— Kimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creation Under Unauthorized Projects

Quick assessment

Affected
kimai kimai
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kimai 是一款开源的时间追踪应用。在 2.57.0 版本之前,针对 和 的 GET 或 POST 请求仅需具备通用的 或 权限即可执行,而不会校验用户对所传入的 Project 或 Customer 对象是否具有编辑权限。因此,知道有效 project.id 或 customer 标识符的用户可以利用 或 中的预设父级创建逻辑,在未获得授权的情况下,将新的子业务对象挂在一个未授权的父级之下,从而污染项目或客户配置,并影响后续的时间条目记录、费率、报表及计费行为。该问题已在 2.57.0 版本中修复。

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-52821

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creation Under Unauthorized Projects
Source: CVE Program / CVE List V5
Vulnerability Description
Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{project} and /en/admin/project/create/{customer} require only the generic create_activity or create_project capability and do not verify edit access to the supplied Project or Customer object. A user who knows a valid project.id or customer identifier can use the preset-parent creation logic in src/Controller/ActivityController.php or src/Controller/ProjectController.php to persist a new child business object under an unauthorized parent, polluting project or customer configuration and influencing later time-entry, rate, reporting, and billing behavior. This issue is fixed in version 2.57.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
kimai kimai < 2.57.0 -

II. Public POCs for CVE-2026-52821

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-52821

登录查看更多情报信息。

Patches & Fixes for CVE-2026-52821 (1)

Vendor Advisories for CVE-2026-52821 (1)

Vendor Pages for CVE-2026-52821 (1)

Same Patch Batch · kimai · 2026-09-15 · 10 CVEs total

CVE-2026-52824 9.1 CRITICAL Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover
CVE-2026-52827 7.1 HIGH Kimai: Two-factor authentication bypass on the Kimai API
CVE-2026-52819 6.3 MEDIUM Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' ti
CVE-2026-52825 5.3 MEDIUM Kimai: Improper Authorization in Kimai Team Member and Team Activity Assignment APIs Allow
CVE-2026-52820 5.3 MEDIUM Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_buil
CVE-2026-52823 5.3 MEDIUM Kimai: Login CSRF in Kimai Timesheet Stop and Restart API Endpoints Allows Unauthorized St
CVE-2026-52826 5.3 MEDIUM Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints
CVE-2026-52828 5.3 MEDIUM Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access
CVE-2026-52822 5.3 MEDIUM Kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timeshee

IV. Related Vulnerabilities

V. Comments for CVE-2026-52821

No comments yet


Leave a comment