Incorrect authorization in kimai2 - CVE-2026-52819
Published: June 29, 2026
kimai2
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in GET /api/timesheets when processing user-supplied user filters. A remote user can send a crafted request with user or users[] parameters to disclose sensitive information.
The issue affects the list endpoint but not the per-record endpoint, and exposed data can include timesheet details and financial fields such as rate and internalRate.