Kimai 是一款开源的时间跟踪应用程序。在 2.58.0 版本之前, 、 以及 Web 端的“重复”工作流允许用户从其拥有的历史时间记录派生新的时间记录,即使该用户访问对应项目或活动的权限已被撤销。 具体来说, 在检查“本人时间记录”权限时,未同时验证用户对相关项目和活动的当前团队访问权限;其 逻辑虽然校验了对象可见性,但未验证用户是否仍具有对引用项目和活动的团队访问权限。因此,一条旧的时间记录实际上成为一种持久的“权限凭证”,使攻击者能够在已被撤销权限的项目和活动下创建新的时间记录,从而在管理权限撤销后,污染预
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-52824 | 9.1 CRITICAL | Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover |
| CVE-2026-52827 | 7.1 HIGH | Kimai: Two-factor authentication bypass on the Kimai API |
| CVE-2026-52819 | 6.3 MEDIUM | Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' ti |
| CVE-2026-52825 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Team Member and Team Activity Assignment APIs Allow |
| CVE-2026-52820 | 5.3 MEDIUM | Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_buil |
| CVE-2026-52823 | 5.3 MEDIUM | Kimai: Login CSRF in Kimai Timesheet Stop and Restart API Endpoints Allows Unauthorized St |
| CVE-2026-52821 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creati |
| CVE-2026-52826 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints |
| CVE-2026-52828 | 5.3 MEDIUM | Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access |
No comments yet