Description
Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}/stop and GET /api/timesheets/{id}/restart, which reuse an authenticated browser session and perform state-changing operations through GET requests without a request-forgery defense. A remote attacker can cause a logged-in user to request either route from attacker-controlled content, stopping a running timesheet or restarting a historical entry to create and start a new timesheet without the user's consent. The unauthorized changes can corrupt time records, billing, reports, approvals, and audits. This issue is fixed in version 2.58.0.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Automated, unauthorized state changes via CSRF on timesheet endpoints
Action: Patch
AI Analysis

Impact

Kimai’s TimesheetController exposes two GET endpoints—/api/timesheets/{id}/stop and /api/timesheets/{id}/restart—that modify the state of a timesheet without requiring a request‑forgery measure. The flaw allows a malicious party to induce a logged‑in user to click or otherwise trigger these URLs from attacker‑controlled content, causing the timesheet to be stopped or a historical entry to be restarted. Such unauthorized alterations can corrupt collective in‑house records, as well as downstream billing, reporting, approvals, and audit trails.

Affected Systems

The vulnerability affects the Kimai time‑tracking application prior to version 2.58.0. All versions before this release expose the vulnerable GET routes. The issue was remedied in Kimai 2.58.0, which removes or protects these endpoints.

Risk and Exploitability

The CVSS score is 5.3, indicating a moderate threat level. The EPSS score is below 1%, suggesting a low probability of exploitation at this time, and the flaw is not currently listed in the CISA KEV catalog. The attack vector requires an authenticated session; a CSRF vector can be executed by embedding or displaying the target URLs within hostile web content and persuading a user to load it. Existing safeguards such as strict same‑origin policies can mitigate the risk, but the lack of a CSRF token on these URIs removes the single most effective barrier against this form of attack.

Generated by OpenCVE AI on September 17, 2026 at 17:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kimai to version 2.58.0 or later where the CSRF protection is applied to the stop and restart endpoints
  • If an upgrade cannot be performed immediately, block or remove the GET /api/timesheets/{id}/stop and /api/timesheets/{id}/restart routes and enforce CSRF tokens for any remaining state‑changing operations
  • Monitor application logs for unexpected or unauthenticated requests to the /api/timesheets stop or restart endpoints to detect potential abuse

Generated by OpenCVE AI on September 17, 2026 at 17:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-r8vr-m544-qh4h Kimai: Login CSRF in the Timesheet Stop and Restart API Endpoints Allows Unauthorized State Changes
History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Kimai
Kimai kimai
Vendors & Products Kimai
Kimai kimai

Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}/stop and GET /api/timesheets/{id}/restart, which reuse an authenticated browser session and perform state-changing operations through GET requests without a request-forgery defense. A remote attacker can cause a logged-in user to request either route from attacker-controlled content, stopping a running timesheet or restarting a historical entry to create and start a new timesheet without the user's consent. The unauthorized changes can corrupt time records, billing, reports, approvals, and audits. This issue is fixed in version 2.58.0.
Title Kimai: Login CSRF in Kimai Timesheet Stop and Restart API Endpoints Allows Unauthorized State Changes
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T13:52:24.796Z

Reserved: 2026-06-08T18:11:06.661Z

Link: CVE-2026-52823

cve-icon Vulnrichment

Updated: 2026-09-15T13:25:11.325Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:09.400

Modified: 2026-09-23T18:22:16.503

Link: CVE-2026-52823

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)