
CVE-2026-40486 Kimai is an open-source time tracking application. In versions 2.52.0 and below, the User Preferences API endpoint (PATCH /api/users/{id}/preferences) applies submitt… https://www.cve.org/CVERecord?id=CVE-2026-40486
Post summary
The excerpt is a brief disclosure of CVE‑2026‑40486, noting a vulnerability in the User Preferences API endpoint of the Kimai time‑tracking application for versions 2.52.0 and older; no PoC, exploit, patch, or active exploitation details are provided.

