Authorization bypass through user-controlled key in kimai2 - CVE-2026-52821
Published: June 29, 2026
kimai2
Detailed vulnerability description
The vulnerability allows a remote user to create business objects under unauthorized projects.
The vulnerability exists due to improper access control in the activity creation flow when handling requests with a preset project identifier. A remote user can send a crafted request with a valid project identifier to create business objects under unauthorized projects.
The issue is persistent and requires knowledge of a valid project identifier.