CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-52819

mediumcovered by 1 sourcefirst seen 2026-07-13
Summary GET /api/timesheets?user=<id> (and users[]=<id>) returns the targeted user's timesheet records to any caller that has the view_other_timesheet permission, without verifying that the caller is teamlead of any team containing the target user. The per-record endpoint GET /api/timesheets/{id} correctly enforces this check via TimesheetVoter/RolePermissionManager::checkTeamAccessTimesheet → checkTeamLeadAccess, but the list endpoint only filters projects/customers by team membership and never validates t.user. A ROLE_TEAMLEAD user can therefore enumerate any user's records — including the rate field — as long as those records are on a project with no team scoping (Kimai's default) or on any project that shares any team (membership, not lead) with the requester. Details Root cause: authorization mismatch between the per-record voter and the list endpoint. Per-record path (correct) src/Voter/TimesheetVoter.php:138: if (!$this->permissionManager->checkTeamAccessTimesheet($subject, $user)) { return false; } return $this->permissionManager->hasRolePermission($user, $permission . '_other_timesheet'); checkTeamLeadAccess (RolePermissionManager.php:143-160) requires isTeamleadOf (not just member) one of the target user's teams. The unit test testTeamleadDeniedWhenOnlyPlainMemberOfOwnerTeam (tests/Voter/TimesheetVoterTest.php:253-269) codifies this: *"a TEAMLEAD role with view_other_timesheet must not access another user's timesheet by being a plain team member — they must be the team's teamlead."* List path (vulnerable) src/API/TimesheetController.php:97-119: public function cgetAction(ParamFetcherInterface $paramFetcher, ..., UserRepository $userRepository): Response { $query = new TimesheetQuery(false); $this->prepareQuery($query, $paramFetcher); $seeAll = false; if ($this->isGranted('view_other_timesheet')) { /** @var array<int> $users */ $users = $paramFetcher->get('users'); $userId = $paramFetcher->get('user'); if ('all' === $userId) { $seeAll = true; }

⚡ Watch CVE-2026-52819

Get an email if CVE-2026-52819 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-52819

CVE.org record

Embed the live status

CVE-2026-52819 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-52819 status](https://www.csirts.com/badge/CVE-2026-52819)](https://www.csirts.com/cve/CVE-2026-52819)