CVE-2026-52819 | Kimai up to 2.56.x /api/timesheets cgetAction users[] privileges management
A vulnerability identified as problematic has been detected in Kimai up to 2.56.x. This issue affects the function TimesheetController::cgetAction of the file /api/timesheets. Performing a manipulation of the argument users[] results in improper privilege management.
This vulnerability was named CVE-2026-52819. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More