Impact
Kimai’s team member and activity assignment APIs allow a teamlead to add userslead’s authorized scope. The vulnerability arises because the POST endpoints /api/teams/{id}/members/{userId} and /api/teams/{id}/activities/{activityId} verify that the requester holds do not check whether the referenced user or activity is accessible to that teamlead. As a result, the system accepts links that the teamlead should not be permitted to create. The resulting relationships are trusted by RolePermissionManager::checkTeamAccessActivity and other team‑based access checks and processes that should remain restricted.
Affected Systems
The vulnerability affects any instance of Kimai prior to version 2.58.0. The kimai vendor maintains the application. Users should confirm their current installation version and apply the 2.58.0 release or later to eliminate the issue.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability is moderate. The EPSS score is < 1 %, indicating a low probability of exploitation. The issue does not appear in the CISA KEV catalogue and no publicly demonstrated exploit is known. Attackers would typically target the web API by re‑using existing teamlead credentials to add arbitrary users or activities beyond the intended scope.
OpenCVE Enrichment
Github GHSA