Impact
Kimai, the open‑source time tracking application, allows administrators to revoke a user’s access to a project or activity. Prior to version 2.58.0, the PATCH endpoints /api/timesheets/{id}/restart and /api/timesheets/{id}/duplicate, together with the web duplicate workflow, could derive a new timesheet from an existing historical entry even after a user had lost rights to the referenced project or activity. Because the TimesheetVoter checks the user’s ownership of a timesheet before validating current team access, the system fails to enforce the latest authorization, enabling a persistent capability to create new time records under an unauthorized project and activity, which can corrupt budgets, statistics, reports, and invoices after administrative revocation.
Affected Systems
The affected product is Kimai, the open‑source time tracking application. All releases before 2.58.0 are vulnerable; version 2.58.0 and later include the fix.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate severity impact. The EPSS score of less than 1% suggests a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a legitimate user who previously had access to the targeted project or activity, and the attacker must be able to authenticate against the system to call the restart or duplicate endpoints. Once an authenticated user executes the operation, the system will create a new timesheet that bypasses current authorization checks, providing a persistent capability for unauthorized record creation.
OpenCVE Enrichment
Github GHSA