Threats Tagged 'cve-2026-52819'
View all threats tagged with 'cve-2026-52819'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-52819'
Click on any threat for detailed analysis and mitigation recommendations
Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the target (CVE-2026-52819)CVE-2026-52819 0 Kimai versions prior to 2.57.0 contain an authorization bypass vulnerability in the GET /api/timesheets endpoint. A user with the ROLE_TEAMLEAD and the view_other_timesheet permission can retrieve timesheet records of other users without being the teamlead of the target user's team. This bypass occurs because the list endpoint does not enforce the teamlead check that the per-record endpoint enforces. As a result, sensitive financial data such as rate and internalRate, along with personal activity details, can be disclosed to unauthorized teamlead users. Join the discussion | GCVE Database | 07/13/2026, 23:55:16 UTC Added: 07/14/2026, 09:21:12 UTC |
Showing 1 to 1 of 1 result