CVE-2026-52820 | Kimai up to 2.56.x Team Access Validation getQueryBuilderForFormType project_identifier improper authorization

SecurityVulns

A vulnerability marked as critical has been reported in Kimai up to 2.56.x. The affected element is the function ProjectRepository::getQueryBuilderForFormType of the component Team Access Validation. The manipulation of the argument project_identifier leads to improper authorization.

This vulnerability is referenced as CVE-2026-52820. Remote exploitation of the attack is possible. No exploit is available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More