THREAT OPS › Threat News › [NVD] CVE-2026-49992 — Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exposed through `GET` routes and directly crea
[NVD] CVE-2026-49992 — Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exposed through `GET` routes and directly crea
CVE-2026-49992 CVSS: None Published: 2026-09-11T22:16:37.673
Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exposed through `GET` routes and directly create or reuse a `Team`, add the current user as teamlead, a
Indicators of compromise
- CVE-2026-49992cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-49992