OVERVIEW CVE-2026-40486 is an authorization bypass vulnerability in Kimai, an open-source time tracking application. Versions 2.52.0 and below are affected. The vulnerability exists in the User Preferences API endpoint (PATCH /api/users/{id}/preferences), which fails to enforce role-based access controls when users attempt to modify billing rate fields. Authenticated users can bypass hourly_rate and internal_rate permission restrictions and directly modify their own billing rates, despite lacking the required hourly-rate role permission. SEVERITY The vulnerability has a CVSS v3.1 score of 4.3 (MEDIUM) with a network-based attack vector requiring low complexity and low privileges. The attack requires user authentication but no interaction. The impact is limited to integrity, as attackers can only modify billing rates affecting invoices and timesheet calculations without compromising confidentiality or availability. The FAUCET risk score is 29.0 out of 100, indicating moderate organizational risk. EXPLOITATION STATUS There is no evidence of active exploitation, with an EPSS score of 0.00013 indicating minimal real-world exploit activity. The vulnerability is not included on CISA's Known Exploited Vulnerabilities list and is not considered a priority for threat actors. Exploit code availability and community attention levels are low. The issue was remediated in version 2.53.0, and organizations should prioritize patching to mitigate unauthorized financial tampering risks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.53.0CPE matchmatch criteria | cpe:2.3:a:kimai:kimai:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.