CVE-2026-42267
MEDIUMDescription
Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can create a tag with a formula string as its name (e.g. =SUM(54+51)) via POST /api/tags and assign it to a timesheet. When an admin exports timesheets to XLSX, ArrayFormatter.formatValue() joins tag names with implode() and returns the result unchanged. OpenSpout promotes any =-prefixed string to a FormulaCell, writing <f>SUM(54+51)</f> into the XLSX archive. Excel evaluates the formula when the file is opened. This issue has been patched in version 2.54.0.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| kimai | kimai |
References
Advisories & Patches
Exploits
Other References
Frequently Asked Questions
What is CVE-2026-42267? +
How severe is CVE-2026-42267? +
What products are affected by CVE-2026-42267? +
How do I check if I'm vulnerable to CVE-2026-42267? +
Related Vulnerabilities
Data provided in a request performed to the server while activating a new device are put in a database. Other …
phpLDAPadmin since at least version 1.2.0 through the latest version 1.2.6.7 allows users to export elements from the LDAP directory …
KWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function.
KWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function.
Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are …
CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file …