Missing Authorization in kimai2 - CVE-2026-52822

 

Missing Authorization in kimai2 - CVE-2026-52822

Published: June 29, 2026


Vulnerability identifier: #VU135850
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-52822
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to create new timesheet records under a revoked project and activity combination.

The vulnerability exists due to improper authorization in the timesheet restart and duplicate workflows when handling restart or duplicate requests for historical timesheet entries. A remote user can send a restart or duplicate request for an older owned timesheet to create new timesheet records under a revoked project and activity combination.

The issue affects the API restart and duplicate endpoints as well as the web duplicate flow that reaches the same save logic.


Affected software

kimai2

How to mitigate CVE-2026-52822

Install security update from vendor's website.

kimai2 - update to 2.58.0

External References

Related Security Bulletins