Description
Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{project} and /en/admin/project/create/{customer} require only the generic create_activity or create_project capability and do not verify edit access to the supplied Project or Customer object. A user who knows a valid project.id or customer identifier can use the preset-parent creation logic in src/Controller/ActivityController.php or src/Controller/ProjectController.php to persist a new child business object under an unauthorized parent, polluting project or customer configuration and influencing later time-entry, rate, reporting, and billing behavior. This issue is fixed in version 2.57.0.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

Kimai is an open‑source time‑tracking application that, before version 2.57.0, allowed GET or POST requests to /en/admin/activity/create/{project} or /en/admin/project/create/{customer} to create activities or projects by only requiring the generic create_activity or create_project capability. The system fails to verify the requesting user’s edit rights on the specified project or customer. A user who knows a valid project.id or customer identifier can leverage the preset‑parent creation logic in ActivityController or ProjectController to persist a new child object under an unauthorized parent time‑entry, rate, reporting, and billing data. This improper authorization flaw (CWE‑639, CWE‑862) can be exploited to tamper with critical business information.

Affected Systems

All installations of Kimai up through version 2.56.x are affected. The specific endpoints are /en /en/admin/project/create/{customer}. The official fix is released in version 2.57.0. Any environment running a pre‑2.57.0 build is vulnerable if guess or enumerate valid project or customer identifiers.

Risk and Exploitability

The CVSS score of 5.3 denotes moderate severity. The EPSS score being under 1% indicates a low probability of exploitation in current threat landscapes, and KEV does not list this issue, suggesting it is not a widely observed exploit. However, the attack vector is straightforward: an attacker who can access the application with a user that holds create rights can supply any known project or customer ID and add a new childuting configuration data and potentially affecting revenue or audit trails.

Generated by OpenCVE AI on September 17, 2026 at 17:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kimai to version 2.57.0 or later to apply the vendor supplied fix.
  • Configure role‑based access controls so that only authorized users can exercise the create_activity or create_project capability, and ensure that create operations target parent.
  • Audit existing activities may have occurred during the vulnerability window and correct or delete them as necessary.

Generated by OpenCVE AI on September 17, 2026 at 17:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-3q6q-26vg-v97x Kimai: Improper Authorization Through Activity Creation with Preset Project Allows Creation Under Unauthorized Projects
History

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Kimai
Kimai kimai
Vendors & Products Kimai
Kimai kimai

Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{project} and /en/admin/project/create/{customer} require only the generic create_activity or create_project capability and do not verify edit access to the supplied Project or Customer object. A user who knows a valid project.id or customer identifier can use the preset-parent creation logic in src/Controller/ActivityController.php or src/Controller/ProjectController.php to persist a new child business object under an unauthorized parent, polluting project or customer configuration and influencing later time-entry, rate, reporting, and billing behavior. This issue is fixed in version 2.57.0.
Title Kimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creation Under Unauthorized Projects
Weaknesses CWE-639
CWE-862
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T14:20:56.384Z

Reserved: 2026-06-08T18:11:06.661Z

Link: CVE-2026-52821

cve-icon Vulnrichment

Updated: 2026-09-17T14:20:50.371Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:09.107

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-52821

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key

  • CWE-862

    Missing Authorization