<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T21:41:26.936815+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-292014</id>
    <title>EUVD-2026-292014</title>
    <updated>2026-10-08T21:41:26.939827+00:00</updated>
    <content>EUVD-2026-292014</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-292014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40486</id>
    <title>fkie_cve-2026-40486</title>
    <updated>2026-10-08T21:41:26.939862+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Kimai is an open-source time tracking application. In versions 2.52.0 and below, the User Preferences API endpoint (PATCH /api/users/{id}/preferences) applies submitted preference values without checking the isEnabled() flag on preference objects. Although the hourly_rate and internal_rate fields are correctly marked as disabled for users lacking the hourly-rate role permission, the API ignores this restriction and saves the values directly. Any authenticated user can modify their own billing rates through this endpoint, resulting in unauthorized financial tampering affecting invoices and timesheet calculations. This issue has been fixed in version 2.53.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40486"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qh43-xrjm-4ggp</id>
    <title>GHSA-qh43-xrjm-4ggp — Kimai's User Preferences API allows standard users to modify restricted attributes: hourly_rate, internal_rate</title>
    <updated>2026-10-08T21:41:26.939896+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: kimai/kimai</p>
<p>### Summary
A Mass Assignment / Broken Object Property Level Authorization (BOPA) vulnerability in the User Preferences API allows any authenticated user (even those with the lowest privileges) to arbitrarily modify restricted financial attributes on their profile, specifically their `hourly_rate` and `internal_rate`.</p>
<p>### Details
Kimai restrictively protects the `hourly_rate` and `internal_rate` parameters during standard GUI flow. Users lacking the `hourly-rate` role permissions cannot see or edit these fields via the standard Web Form (`UserApiEditForm` / `UserEditType`).</p>
<p>The vulnerability exists in the dedicated preferences API endpoint: `src/API/UserController.php::updateUserPreference`.</p>
<p>When a `PATCH` request is sent to `/api/users/{id}/preferences`, the endpoint iterates through the submitted JSON array and blindly applies the new values:
```php
foreach ($request-&gt;request-&gt;all() as $preference) {
    // ... validation omitted ...
    if (null === ($meta = $profile-&gt;getPreference($name))) {
        throw $this-&gt;createNotFoundException(\sprintf('Unknown custom-field "%s" requested', $name));
    }</p>
<p>$meta-&gt;setValue($value); // &lt;-- VULNERABILITY
}
```</p>
<p>The underlying Role-Based Access Control logic (`UserPreferenceSubscriber::getDefaultPreferences`) accurately identifies that standard users lack the `hourly-rate` role, and flags the dynamically generated preference object as disabled (`$preference-&gt;setEnabled(false)`).</p>
<p>However, the `updateUserPreference` API endp…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qh43-xrjm-4ggp"/>
  </entry>
</feed>
