CVE-2026-52825 | Kimai up to 2.57.x Team API getQueryBuilderForFormType improper authorization

SecurityVulns

A vulnerability described as problematic has been identified in Kimai up to 2.57.x. The impacted element is the function UserRepository::getQueryBuilderForFormType of the component Team API. The manipulation results in improper authorization.

This vulnerability is identified as CVE-2026-52825. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More