CVE-2026-52828

medium

Description

Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportController::editExportTemplate() inherit only the class-level create_export permission, which ROLE_TEAMLEAD receives by default, and omit the create_export_template permission required by the API routes and user interface. A teamlead can directly access the export template creation and editing web routes to create or modify global ExportTemplate records marked available to all users, altering export columns, renderer, format, and output used by other users and administrators. This issue is fixed in version 2.58.0.

References

https://www.kimai.org/en/security/ghsa-rw46-qg69-vg6h

https://github.com/kimai/kimai/security/advisories/GHSA-rw46-qg69-vg6h

https://github.com/kimai/kimai/releases/tag/2.58.0

https://github.com/kimai/kimai/pull/5952

https://github.com/kimai/kimai/commit/31a8f887a5cda517db7b4320a7ad997c87d08601

Details

Source: Mitre, NVD

Published: 2026-09-15

Updated: 2026-09-23

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Severity: Medium

CVSS v4

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00396