Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-52825— Kimai: Improper Authorization in Kimai Team Member and Team Activity Assignment APIs Allows Expansion of Team Scope Beyond Authorized Visibility

Quick assessment

Affected
kimai kimai
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

KiMi是一款开源的时间追踪应用。在2.58.0版本之前, 和 这两个端点会验证团队领导(teamlead)是否有权限编辑团队,但未验证所引用的用户是否具备 权限,也未验证所引用的活动是否具备查看(view)权限。 团队领导可以将超出其可管理范围的(非其团队内的)用户或活动添加到一个可编辑的团队中,从而绕过 和 所强制实施的较窄选择范围。由此产生的关联关系可能被 以及其他基于团队的授权、可见性、报表和工作流逻辑所信赖,从而导致权限控制失效。 该问题已在2.58.0版本中修复。

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-52825

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kimai: Improper Authorization in Kimai Team Member and Team Activity Assignment APIs Allows Expansion of Team Scope Beyond Authorized Visibility
Source: CVE Program / CVE List V5
Vulnerability Description
Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/teams/{id}/activities/{activityId} verify that a teamlead may edit the Team but do not verify access_user for the referenced User or view access for the referenced Activity. A teamlead can add users or activities outside the teamlead's manageable scope to an editable team, bypassing the narrower choices enforced by TeamEditForm and UserRepository::getQueryBuilderForFormType(). The resulting relationships can be trusted by RolePermissionManager::checkTeamAccessActivity() and other team-based authorization, visibility, reporting, and workflow logic. This issue is fixed in version 2.58.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
kimai kimai < 2.58.0 -

II. Public POCs for CVE-2026-52825

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-52825

登录查看更多情报信息。

Patches & Fixes for CVE-2026-52825 (1)

Vendor Advisories for CVE-2026-52825 (2)

Vendor Pages for CVE-2026-52825 (1)

Same Patch Batch · kimai · 2026-09-15 · 10 CVEs total

CVE-2026-52824 9.1 CRITICAL Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover
CVE-2026-52827 7.1 HIGH Kimai: Two-factor authentication bypass on the Kimai API
CVE-2026-52819 6.3 MEDIUM Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' ti
CVE-2026-52820 5.3 MEDIUM Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_buil
CVE-2026-52823 5.3 MEDIUM Kimai: Login CSRF in Kimai Timesheet Stop and Restart API Endpoints Allows Unauthorized St
CVE-2026-52821 5.3 MEDIUM Kimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creati
CVE-2026-52826 5.3 MEDIUM Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints
CVE-2026-52828 5.3 MEDIUM Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access
CVE-2026-52822 5.3 MEDIUM Kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timeshee

IV. Related Vulnerabilities

V. Comments for CVE-2026-52825

No comments yet


Leave a comment