CVE-2026-40486Disclosure(kimai / kimai)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Kimai is an open-source time tracking application. In versions 2.52.0 and below, the User Preferences API endpoint (PATCH /api/users/{id}/preferences) applies submitted preference values without checking the isEnabled() flag on preference objects. Although the hourly_rate and internal_rate fields are correctly marked as disabled for users lacking the hourly-rate role permission, the API ignores this restriction and saves the values directly. Any authenticated user can modify their own billing rates through this endpoint, resulting in unauthorized financial tampering affecting invoices and timesheet calculations. This issue has been fixed in version 2.53.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-915

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kimai

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-16); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
kimai

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-16: 1Mentions · 2026-04-18: 1Technical Details · 2026-04-18: 104-1604-18
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-40486 Kimai is an open-source time tracking application. In versions 2.52.0 and below, the User Preferences API endpoint (PATCH /api/users/{id}/preferences) applies submitt… https://www.cve.org/CVERecord?id=CVE-2026-40486

    Post summary

    The excerpt is a brief disclosure of CVE‑2026‑40486, noting a vulnerability in the User Preferences API endpoint of the Kimai time‑tracking application for versions 2.52.0 and older; no PoC, exploit, patch, or active exploitation details are provided.

    00000170
    57.2K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Kimai, Mass Assignment / BOPA Vulnerability, #CVE-2026-40486 (Moderate) https://dailycve.com/kimai-mass-assignment-bopa-vulnerability-cve-2026-40486-moderate/

    Post summary

    The post announces a moderate‑severity Mass Assignment/BOPA vulnerability (CVE‑2026‑40486) in Kimai, without providing any PoC, exploit details, or mitigation information.

    0000029
    181 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkimaikimai---

Explore more