Kimai 是一款开源的时间跟踪应用程序。在 2.58.0 版本之前, 暴露了 和 两个接口。这两个接口复用已认证的浏览器会话,并通过 GET 请求执行状态变更操作,但缺乏请求伪造(CSRF)防护机制。远程攻击者可以通过攻击者控制的内容,诱导已登录的用户访问上述任一路由,从而在未获得用户同意的情况下停止正在运行的工时记录,或重启历史工时条目并自动创建并启动新的工时记录。这些未经授权的变更可能导致时间记录、账单、报表、审批及审计数据遭到破坏。该问题已在 2.58.0 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-52824 | 9.1 CRITICAL | Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover |
| CVE-2026-52827 | 7.1 HIGH | Kimai: Two-factor authentication bypass on the Kimai API |
| CVE-2026-52819 | 6.3 MEDIUM | Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' ti |
| CVE-2026-52825 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Team Member and Team Activity Assignment APIs Allow |
| CVE-2026-52820 | 5.3 MEDIUM | Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_buil |
| CVE-2026-52821 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creati |
| CVE-2026-52826 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints |
| CVE-2026-52828 | 5.3 MEDIUM | Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access |
| CVE-2026-52822 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timeshee |
No comments yet