Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-52827— Kimai: Two-factor authentication bypass on the Kimai API

Quick assessment

Affected
kimai kimai
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kimai 是一个开源的时间跟踪应用。在 2.59.0 之前,在密码验证后、TOTP 验证完成前签发的 cookie 会被所有 路由接受。原因是 使用 规则保护 API,而 会将已存在的会话通过主防火墙进行路由。由于 满足该访问控制规则,且 向该令牌所属用户授予了 API 访问权限,因此攻击者在拥有有效账户密码的情况下,无需输入第二因素(如 TOTP 动态验证码)即可使用已认证的 REST API 操作,尽管 Web 路由仍被拦截。该问题已在版本 2.59.0 中修复。

CVSS 7.1 · High

Possible ATT&CK Techniques 1 AI

T1567 · Exfiltration Over Web Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-52827

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kimai: Two-factor authentication bypass on the Kimai API
Source: CVE Program / CVE List V5
Vulnerability Description
Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verification but before TOTP completion is accepted by every /api route because config/packages/security.yaml protects the API with IS_AUTHENTICATED and App\API\Authentication\ApiRequestMatcher routes an existing session through the main firewall. A Scheb TwoFactorToken satisfies that access rule, and App\Voter\ApiVoter grants API access to its User, allowing an attacker with a valid account password to use authenticated REST API operations without entering the second factor even though web routes remain blocked. This issue is fixed in version 2.59.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
kimai kimai < 2.59.0 -

II. Public POCs for CVE-2026-52827

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-52827

登录查看更多情报信息。

Patches & Fixes for CVE-2026-52827 (1)

Vendor Advisories for CVE-2026-52827 (2)

Vendor Pages for CVE-2026-52827 (1)

Same Patch Batch · kimai · 2026-09-15 · 10 CVEs total

CVE-2026-52824 9.1 CRITICAL Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover
CVE-2026-52819 6.3 MEDIUM Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' ti
CVE-2026-52825 5.3 MEDIUM Kimai: Improper Authorization in Kimai Team Member and Team Activity Assignment APIs Allow
CVE-2026-52820 5.3 MEDIUM Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_buil
CVE-2026-52823 5.3 MEDIUM Kimai: Login CSRF in Kimai Timesheet Stop and Restart API Endpoints Allows Unauthorized St
CVE-2026-52821 5.3 MEDIUM Kimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creati
CVE-2026-52826 5.3 MEDIUM Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints
CVE-2026-52828 5.3 MEDIUM Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access
CVE-2026-52822 5.3 MEDIUM Kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timeshee

IV. Related Vulnerabilities

V. Comments for CVE-2026-52827

No comments yet


Leave a comment