
🚨*CVE* CVE-2026-42267 Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can create a tag with a formula string as its name (e.g… https://www.cve.org/CVERecord?id=CVE-2026-42267 ----- Traducción: CVE-2026-42267 Kim… http://infoflow.cloud`
Post summary
CVE‑2026‑42267 is disclosed as a flaw in Kimai where ROLE_USERs can create tags with formula strings, potentially enabling exploitation. No PoC, patch, or active exploitation evidence is provided.


