Description
Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/teams/{id}/activities/{activityId} verify that a teamlead may edit the Team but do not verify access_user for the referenced User or view access for the referenced Activity. A teamlead can add users or activities outside the teamlead's manageable scope to an editable team, bypassing the narrower choices enforced by TeamEditForm and UserRepository::getQueryBuilderForFormType(). The resulting relationships can be trusted by RolePermissionManager::checkTeamAccessActivity() and other team-based authorization, visibility, reporting, and workflow logic. This issue is fixed in version 2.58.0.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized team scope expansion and potential data exposure
Action: Patch immediately
AI Analysis

Impact

Kimai’s team member and activity assignment APIs allow a teamlead to add userslead’s authorized scope. The vulnerability arises because the POST endpoints /api/teams/{id}/members/{userId} and /api/teams/{id}/activities/{activityId} verify that the requester holds do not check whether the referenced user or activity is accessible to that teamlead. As a result, the system accepts links that the teamlead should not be permitted to create. The resulting relationships are trusted by RolePermissionManager::checkTeamAccessActivity and other team‑based access checks and processes that should remain restricted.

Affected Systems

The vulnerability affects any instance of Kimai prior to version 2.58.0. The kimai vendor maintains the application. Users should confirm their current installation version and apply the 2.58.0 release or later to eliminate the issue.

Risk and Exploitability

With a CVSS score of 5.3 the vulnerability is moderate. The EPSS score is < 1 %, indicating a low probability of exploitation. The issue does not appear in the CISA KEV catalogue and no publicly demonstrated exploit is known. Attackers would typically target the web API by re‑using existing teamlead credentials to add arbitrary users or activities beyond the intended scope.

Generated by OpenCVE AI on September 17, 2026 at 17:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kimai to version 2.58.0 or later, which contains the authorization fix
  • Immediately audit existing teams for any members or activities that were added outside the intended scope and remove them
  • If an upgrade is not feasible, establish a manual review process to enforce that any new team members or activities are verified against the teamlead’s valid scope before acceptance
  • Revoke any unnecessary teamlead privileges on teams that do not require such permissions, reducing the attack surface

Generated by OpenCVE AI on September 17, 2026 at 17:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xv4r-4885-gwpg Kimai has Improper Authorization in Team Member and Team Activity Assignment APIs Which Allows Expansion of Team Scope Beyond Authorized Visibility
History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Kimai
Kimai kimai
Vendors & Products Kimai
Kimai kimai

Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/teams/{id}/activities/{activityId} verify that a teamlead may edit the Team but do not verify access_user for the referenced User or view access for the referenced Activity. A teamlead can add users or activities outside the teamlead's manageable scope to an editable team, bypassing the narrower choices enforced by TeamEditForm and UserRepository::getQueryBuilderForFormType(). The resulting relationships can be trusted by RolePermissionManager::checkTeamAccessActivity() and other team-based authorization, visibility, reporting, and workflow logic. This issue is fixed in version 2.58.0.
Title Kimai: Improper Authorization in Kimai Team Member and Team Activity Assignment APIs Allows Expansion of Team Scope Beyond Authorized Visibility
Weaknesses CWE-285
CWE-862
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T12:34:38.943Z

Reserved: 2026-06-08T18:11:06.661Z

Link: CVE-2026-52825

cve-icon Vulnrichment

Updated: 2026-09-15T12:34:28.995Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:09.687

Modified: 2026-09-23T18:22:16.503

Link: CVE-2026-52825

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses