Missing Authorization in kimai2 - CVE-2026-52825

 

Missing Authorization in kimai2 - CVE-2026-52825

Published: June 29, 2026


Vulnerability identifier: #VU135848
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-52825
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to expand team scope beyond authorized visibility.

The vulnerability exists due to improper authorization in the Team member assignment API when handling crafted backend API requests to add users to an editable team. A remote user can send a specially crafted API request to expand team scope beyond authorized visibility.

Once the unauthorized team relationship is created, downstream authorization and visibility decisions may treat it as legitimate.


Affected software

kimai2

How to mitigate CVE-2026-52825

Install security update from vendor's website.

kimai2 - update to 2.58.0

External References

Related Security Bulletins