---
id: CVE-2026-52828
title: Kimai is an open-source time tracking application
summary: >-
  Kimai is an open-source time tracking application. Prior to 2.58.0,
  ExportController::createExportTemplate() and
  ExportController::editExportTemplate() inherit only the class-level
  create_export permission, which ROLE_TEAMLEAD receives b…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-862
vendor: kimai
product: kimai
affected:
  - kimai < 2.58.0
patched:
  - kimai/kimai 2.58.0
published: '2026-09-15'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:22:16.503'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-52828'
references:
  - url: >-
      https://github.com/kimai/kimai/commit/31a8f887a5cda517db7b4320a7ad997c87d08601
    label: security-advisories@github.com
  - url: 'https://github.com/kimai/kimai/pull/5952'
    label: security-advisories@github.com
  - url: 'https://github.com/kimai/kimai/releases/tag/2.58.0'
    label: security-advisories@github.com
  - url: 'https://github.com/kimai/kimai/security/advisories/GHSA-rw46-qg69-vg6h'
    label: security-advisories@github.com
  - url: 'https://www.kimai.org/en/security/ghsa-rw46-qg69-vg6h'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-rw46-qg69-vg6h'
tags:
  - nvd
  - cve.org
  - ghsa
  - composer
epss: 0.00356
epssPercentile: 0.29399
aliases:
  - GHSA-rw46-qg69-vg6h
ecosystem: composer
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T12:27:56.746725Z'
cvssSource: cna
ingestedAt: '2026-07-14T01:32:35.834Z'
---

## Overview

Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportController::editExportTemplate() inherit only the class-level create_export permission, which ROLE_TEAMLEAD receives by default, and omit the create_export_template permission required by the API routes and user interface. A teamlead can directly access the export template creation and editing web routes to create or modify global ExportTemplate records marked available to all users, altering export columns, renderer, format, and output used by other users and administrators. This issue is fixed in version 2.58.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-52828)

Affected packages:

- `kimai/kimai <= 2.57.0`

Patched in:

- `kimai/kimai 2.58.0`

Source: https://github.com/advisories/GHSA-rw46-qg69-vg6h
