CVE-2026-40486: Kimai's User Preferences API allows standard users to modify restricted attributes: hourly_rate, internal_rate
(updated )
A Mass Assignment / Broken Object Property Level Authorization (BOPA) vulnerability in the User Preferences API allows any authenticated user (even those with the lowest privileges) to arbitrarily modify restricted financial attributes on their profile, specifically their hourly_rate and internal_rate.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-40486 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →