Description
Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user and users[] target identifiers from a caller with view_other_timesheet but does not apply access_user or verify that a ROLE_TEAMLEAD requester leads a team containing each target user. TimesheetController::cgetAction() adds the resolved users directly to the query while project and customer filtering still permits records on unscoped projects or projects sharing ordinary team membership, allowing a teamlead to retrieve another user's descriptions, timing data, tags, rate, and internalRate even though GET /api/timesheets/{id} would deny access through TimesheetVoter. This issue is fixed in version 2.57.0.
Published: 2026-09-15
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Patch
AI Analysis

Impact

The vulnerability is an authorization bypass (CWE‑863) in Kimai’s GET /api/timesheets endpoint. Prior to version 2.57.0, the controller accepts user or users[] identifiers from any caller holding the view_other_timesheet role. It does not verify that the requester is a team lead for those users nor does it apply the access_user check, allowing the requester to include those target user IDs directly in the query. As a result, an authorized but non‑team‑lead user can retrieve full details of other users’ timesheet entries—including descriptions, timing data, tags, rate, and internalRate—over projects or customers that are not scoped to the requester. This flaw therefore compromises confidentiality of timesheet data for all users whose entries can be accessed through the API by a non‑team‑lead with view_other_timesheet permission.

Affected Systems

Kimai 1.x and 2.x releases older than 2.57.0 are impacted. The vulnerability exists in the default Kimai installation for any user who holds the view_other_timesheet role, regardless of team membership. No specific sub‑versions are listed beyond the cut‑off of 2.57.0, so all earlier releases should be considered vulnerable.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate security impact, while the EPSS score of < 1 % reflects a low probability of exploitation in the wild at the time not listed in the CISA KEV catalog. An attacker can exploit the flaw by issuing a simple GET request to /api/timesheets with appropriate user identifiers while possessing the view_other_timesheet permission. The security implications are confined to data confidentiality for the corresponding users; there is no direct impact on system integrity or availability.

Generated by OpenCVE AI on September 17, 2026 at 17:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kimai to version 2.57.0 or newer to remove the bypass
  • Revoke the view_other_timesheet permission from all users who are not team leads
  • If immediate upgrade is not feasible, restrict access to the /api/timesheets endpoint to trusted networks or internal users only

Generated by OpenCVE AI on September 17, 2026 at 17:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4m8q-55qv-9pwp Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the target
History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Kimai
Kimai kimai
Vendors & Products Kimai
Kimai kimai

Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user and users[] target identifiers from a caller with view_other_timesheet but does not apply access_user or verify that a ROLE_TEAMLEAD requester leads a team containing each target user. TimesheetController::cgetAction() adds the resolved users directly to the query while project and customer filtering still permits records on unscoped projects or projects sharing ordinary team membership, allowing a teamlead to retrieve another user's descriptions, timing data, tags, rate, and internalRate even though GET /api/timesheets/{id} would deny access through TimesheetVoter. This issue is fixed in version 2.57.0.
Title Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the target
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T15:17:07.990Z

Reserved: 2026-06-08T18:11:06.661Z

Link: CVE-2026-52819

cve-icon Vulnrichment

Updated: 2026-09-15T15:16:13.091Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:08.800

Modified: 2026-09-23T18:22:16.503

Link: CVE-2026-52819

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses