Description
Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/timesheets/{id}/duplicate, and the web duplicate workflow can derive a new record from an owned historical timesheet after the user's access to its project or activity has been revoked. TimesheetVoter evaluates the own-timesheet permission before current team access, and its canStart() logic validates object visibility but does not verify the user's current team access to the referenced project and activity. An old entry therefore acts as a persistent capability to create new time records under an unauthorized project and activity, corrupting budgets, statistics, reports, and invoices after an administrative revocation. This issue is fixed in version 2.58.0.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized creation of timesheets under revoked projects
Action: Immediate Patch
AI Analysis

Impact

Kimai, the open‑source time tracking application, allows administrators to revoke a user’s access to a project or activity. Prior to version 2.58.0, the PATCH endpoints /api/timesheets/{id}/restart and /api/timesheets/{id}/duplicate, together with the web duplicate workflow, could derive a new timesheet from an existing historical entry even after a user had lost rights to the referenced project or activity. Because the TimesheetVoter checks the user’s ownership of a timesheet before validating current team access, the system fails to enforce the latest authorization, enabling a persistent capability to create new time records under an unauthorized project and activity, which can corrupt budgets, statistics, reports, and invoices after administrative revocation.

Affected Systems

The affected product is Kimai, the open‑source time tracking application. All releases before 2.58.0 are vulnerable; version 2.58.0 and later include the fix.

Risk and Exploitability

The CVSS score is 5.3, indicating a moderate severity impact. The EPSS score of less than 1% suggests a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a legitimate user who previously had access to the targeted project or activity, and the attacker must be able to authenticate against the system to call the restart or duplicate endpoints. Once an authenticated user executes the operation, the system will create a new timesheet that bypasses current authorization checks, providing a persistent capability for unauthorized record creation.

Generated by OpenCVE AI on September 17, 2026 at 17:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kimai to version 2.58.0 or later to apply the vendor patch.
  • Revoke any residual access for users who had previously been granted rights to the affected projects or activities, and reassess any timesheets that were duplicated or restarted after revocation.
  • Audit existing timesheet logs for unauthorized entries created after the revocation period and correct budgets, statistics, and invoices accordingly.

Generated by OpenCVE AI on September 17, 2026 at 17:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-c6w6-57jj-62vh Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access Revocation
History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Kimai
Kimai kimai
Vendors & Products Kimai
Kimai kimai

Tue, 15 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/timesheets/{id}/duplicate, and the web duplicate workflow can derive a new record from an owned historical timesheet after the user's access to its project or activity has been revoked. TimesheetVoter evaluates the own-timesheet permission before current team access, and its canStart() logic validates object visibility but does not verify the user's current team access to the referenced project and activity. An old entry therefore acts as a persistent capability to create new time records under an unauthorized project and activity, corrupting budgets, statistics, reports, and invoices after an administrative revocation. This issue is fixed in version 2.58.0.
Title Kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access Revocation
Weaknesses CWE-285
CWE-862
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T13:52:17.628Z

Reserved: 2026-06-08T18:11:06.661Z

Link: CVE-2026-52822

cve-icon Vulnrichment

Updated: 2026-09-15T13:25:09.091Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:09.250

Modified: 2026-09-23T18:22:16.503

Link: CVE-2026-52822

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses