THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-49992 — Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exposed through `GET` routes and directly crea

[NVD] CVE-2026-49992 — Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exposed through `GET` routes and directly crea

mednvdPublished 2026-09-11

CVE-2026-49992 CVSS: None Published: 2026-09-11T22:16:37.673

Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exposed through `GET` routes and directly create or reuse a `Team`, add the current user as teamlead, a

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-49992