CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-52826

mediumcovered by 1 sourcefirst seen 2026-07-14
Summary Kimai 2.56.0 contains an authenticated improper authorization vulnerability in the Web rate editing flows for projects, customers, and activities. A user who can edit one authorized parent object can combine that authorized parent ID with the rate ID of a different, unauthorized parent object and thereby modify the unauthorized rate record. This affects ProjectRate, CustomerRate, and ActivityRate editing. The issue is caused by missing parent-child consistency validation and allows cross-project, cross-customer, or cross-activity tampering of billing-related configuration. Details The issue affects the following Web routes: - GET/POST /en/admin/project/{id}/rate/{rate} - GET/POST /en/admin/customer/{id}/rate/{rate} - GET/POST /en/admin/activity/{id}/rate/{rate} In both cases, the parent object and the rate object are resolved independently from user-controlled route parameters. The controller only checks whether the current user may edit the parent object referenced by {id}, but it does not verify that the child rate object referenced by {rate} actually belongs to that same parent. In these controllers, there is no validation such as: - $rate->getProject() === $project - $rate->getCustomer() === $customer - $rate->getActivity() === $activity This missing binding check is especially notable because the API delete endpoints already enforce the expected parent-child relationship. This shows that parent-child consistency is already a recognized invariant in the application design, but the Web edit endpoints fail to enforce it for projects, customers, and activities. *A PoC was provided, but removed for security reasons.* Impact This vulnerability allows authenticated users to tamper with billing-related rate configuration outside their authorized project, customer, or activity scope. An attacker can modify rate values belonging to other teams or business domains, which can affect time-based settlement, inherited pricing, cost calculations, budget re

⚡ Watch CVE-2026-52826

Get an email if CVE-2026-52826 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-52826

CVE.org record

Embed the live status

CVE-2026-52826 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-52826 status](https://www.csirts.com/badge/CVE-2026-52826)](https://www.csirts.com/cve/CVE-2026-52826)