Description
Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exposed through `GET` routes and directly create or reuse a `Team`, add the current user as teamlead, and bind the target object to that team. As a result, an attacker can trick a logged-in user with the required permissions into visiting a malicious page and cause unauthorized changes to team, teamlead, and object-binding relationships. This is a real authorization-structure modification issue rather than a harmless UI shortcut. Version 2.58.0 patches the issue.
Published: 2026-09-11
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized team and permission structure modification
Action: Apply Patch
AI Analysis

Impact

Kimai, an open‑source time‑tracking application, is vulnerable in versions prior to 2.58.0 due to authenticated cross‑site request forgery in default team‑creation shortcuts for projects, customers, and activities. These shortcuts are exposed through GET routes; they automatically create or reuse a Team, assign the current user as team‑lead, and bind the target object to that team. If a logged‑in user with the requisite permissions is tricked into visiting a malicious URL, the attacker can authorize changes to team, team‑lead, and object‑binding relationships, thereby altering the organization’s team and permission structure. This is a real authorization‑structure modification issue rather than a harmless UI shortcut.

Affected Systems

The affected product is Kimai, an open‑source time‑tracking application. Any deployment using a version earlier than 2.58.0 is vulnerable. Version 2.58.0 onward includes the fix.

Risk and Exploitability

The CVSS base score of 6.3 indicates a moderate risk. The EPSS score is <1%, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploits at the time of analysis. The flaw requires the victim to be authenticated and to possess the permissions needed to create or modify teams. Based on the description, it is inferred that the likely attack vector is a malicious URL that an authenticated user with the necessary permissions is lured to. If successful, the attacker can alter team structure and permissions, potentially compromising the organization’s data access controls.

Generated by OpenCVE AI on September 15, 2026 at 20:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to version 2.58.0 or later to apply the vendor fix.
  • Restrict access to the default team creation endpoints by disabling the default GET shortcuts or enforcing stricter permission checks on these routes.
  • Implement a web application firewall rule to detect and block malicious GET requests to the default team‑creation endpoints.

Generated by OpenCVE AI on September 15, 2026 at 20:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pgcc-vfmc-7cw5 Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Kimai
Kimai kimai
Vendors & Products Kimai
Kimai kimai

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exposed through `GET` routes and directly create or reuse a `Team`, add the current user as teamlead, and bind the target object to that team. As a result, an attacker can trick a logged-in user with the required permissions into visiting a malicious page and cause unauthorized changes to team, teamlead, and object-binding relationships. This is a real authorization-structure modification issue rather than a harmless UI shortcut. Version 2.58.0 patches the issue.
Title Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T16:14:53.650Z

Reserved: 2026-06-02T18:30:51.283Z

Link: CVE-2026-49992

cve-icon Vulnrichment

Updated: 2026-09-14T16:14:50.120Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T22:16:37.673

Modified: 2026-09-23T18:22:16.503

Link: CVE-2026-49992

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:15:14Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)