CVE-2026-52821 | Kimai up to 2.56.x Preset-Parent Creation Logic ActivityController.php project.id/customer improper authorization

SecurityVulns

A vulnerability has been found in Kimai up to 2.56.x and classified as critical. This impacts an unknown function of the file src/Controller/ActivityController.php of the component Preset-Parent Creation Logic. Performing a manipulation of the argument project.id/customer results in improper authorization.

This vulnerability is reported as CVE-2026-52821. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded.VulDB Recent EntriesRead More