CVE-2026-52826
Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/{rate}, /en/admin/customer/{id}/rate/{rate}, and /en/admin/activity/{id}/rate/{rate} independently resolve the authorized parent identifier and the attacker-selected child rate identifier without confirming that the ProjectRate, CustomerRate, or ActivityRate belongs to that parent. An authenticated user who can edit one parent object can pair it with a rate record from an unauthorized project, customer, or activity and persist changes to billing configuration in kimai2_projects_rates, kimai2_customers_rates, or kimai2_activities_rates. This issue is fixed in version 2.57.0.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.26%
- CWE
- CWE-285, CWE-639
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- kimai kimai
Weakness type
Related vulnerabilities
- CVE-2026-66422 — Apache Tomcat: Servlet role references can bypass declarative role constraints
- CVE-2026-55166 — Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOR
- CVE-2026-53952 — GetSimple CMS & GetSimpleCMS-CE have an Unauthenticated Admin Account Creation via Setup Logic Flaw
- CVE-2026-53548 — Termix: IDOR — Authenticated user can fetch SSH passwords for hosts owned by other users
- CVE-2026-73644 — OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user without an ACI proxy grant
- CVE-2026-45052 — OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints
- CVE-2026-48499 — Activepieces: Cross-tenant data exposure and code injection via the Code piece sandbox cache
- CVE-2026-18367 — A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS