CVE-2026-52827
- EPSS 0.43%
- Veröffentlicht 15.09.2026 10:45:03
- Zuletzt bearbeitet 30.09.2026 17:51:56
Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verification but before TOTP completion is accepted by every /api route because config/packages/security.yaml protects the API with IS_...
CVE-2026-52822
- EPSS 0.36%
- Veröffentlicht 15.09.2026 10:44:08
- Zuletzt bearbeitet 23.09.2026 18:22:16
Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/timesheets/{id}/duplicate, and the web duplicate workflow can derive a new record from an owned historical timesheet after the user's a...
CVE-2026-52828
- EPSS 0.36%
- Veröffentlicht 15.09.2026 10:43:09
- Zuletzt bearbeitet 23.09.2026 18:22:16
Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportController::editExportTemplate() inherit only the class-level create_export permission, which ROLE_TEAMLEAD receives by default, an...
CVE-2026-52826
- EPSS 0.26%
- Veröffentlicht 15.09.2026 10:42:13
- Zuletzt bearbeitet 23.09.2026 18:22:16
Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/{rate}, /en/admin/customer/{id}/rate/{rate}, and /en/admin/activity/{id}/rate/{rate} independently resolve the authorized parent i...
CVE-2026-52823
- EPSS 0.21%
- Veröffentlicht 15.09.2026 10:41:17
- Zuletzt bearbeitet 23.09.2026 18:22:16
Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}/stop and GET /api/timesheets/{id}/restart, which reuse an authenticated browser session and perform state-changing operations thr...
CVE-2026-52824
- EPSS 2.06%
- Veröffentlicht 15.09.2026 10:40:28
- Zuletzt bearbeitet 30.09.2026 17:51:56
Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces nor rejects that value before ...
CVE-2026-52825
- EPSS 0.27%
- Veröffentlicht 15.09.2026 10:39:15
- Zuletzt bearbeitet 23.09.2026 18:22:16
Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/teams/{id}/activities/{activityId} verify that a teamlead may edit the Team but do not verify access_user for the referenced User ...
CVE-2026-52821
- EPSS 0.26%
- Veröffentlicht 15.09.2026 10:38:16
- Zuletzt bearbeitet 30.09.2026 17:51:56
Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{project} and /en/admin/project/create/{customer} require only the generic create_activity or create_project capability and do not v...
CVE-2026-52820
- EPSS 0.27%
- Veröffentlicht 15.09.2026 10:37:17
- Zuletzt bearbeitet 23.09.2026 18:22:16
Kimai is an open-source time tracking application. Prior to 2.57.0, PATCH /api/timesheets/{id} and POST /api/timesheets accept a user-controlled project identifier through TimesheetApiEditForm and FormTrait, and ProjectRepository::getQueryBuilderForF...
CVE-2026-52819
- EPSS 0.37%
- Veröffentlicht 15.09.2026 10:36:02
- Zuletzt bearbeitet 23.09.2026 18:22:16
Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user and users[] target identifiers from a caller with view_other_timesheet but does not apply access_user or verify that a ROLE_TEAMLEA...