Impact
The vulnerability is an authorization bypass (CWE‑863) in Kimai’s GET /api/timesheets endpoint. Prior to version 2.57.0, the controller accepts user or users[] identifiers from any caller holding the view_other_timesheet role. It does not verify that the requester is a team lead for those users nor does it apply the access_user check, allowing the requester to include those target user IDs directly in the query. As a result, an authorized but non‑team‑lead user can retrieve full details of other users’ timesheet entries—including descriptions, timing data, tags, rate, and internalRate—over projects or customers that are not scoped to the requester. This flaw therefore compromises confidentiality of timesheet data for all users whose entries can be accessed through the API by a non‑team‑lead with view_other_timesheet permission.
Affected Systems
Kimai 1.x and 2.x releases older than 2.57.0 are impacted. The vulnerability exists in the default Kimai installation for any user who holds the view_other_timesheet role, regardless of team membership. No specific sub‑versions are listed beyond the cut‑off of 2.57.0, so all earlier releases should be considered vulnerable.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate security impact, while the EPSS score of < 1 % reflects a low probability of exploitation in the wild at the time not listed in the CISA KEV catalog. An attacker can exploit the flaw by issuing a simple GET request to /api/timesheets with appropriate user identifiers while possessing the view_other_timesheet permission. The security implications are confined to data confidentiality for the corresponding users; there is no direct impact on system integrity or availability.
OpenCVE Enrichment
Github GHSA