Description
Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/{rate}, /en/admin/customer/{id}/rate/{rate}, and /en/admin/activity/{id}/rate/{rate} independently resolve the authorized parent identifier and the attacker-selected child rate identifier without confirming that the ProjectRate, CustomerRate, or ActivityRate belongs to that parent. An authenticated user who can edit one parent object can pair it with a rate record from an unauthorized project, customer, or activity and persist changes to billing configuration in kimai2_projects_rates, kimai2_customers_rates, or kimai2_activities_rates. This issue is fixed in version 2.57.0.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Rate Modification
Action: Immediate Patch
AI Analysis

Impact

An, customer, or activity can change the rate used for billing because the system separately resolves the parent object’s identifier and the attacker‑selected child rate identifier without verifying that the chosen rate actually belongs to that parent. The flaw allows pairing a rate record that does not belong to the specified project, customer, or activity and persisting the change in the kimai2_*_rates tables. This results in an integrity violation, where legitimate billing data can be altered to overcharge or undercharge customers, potentially causing financial loss or contractual disputes.

Affected Systems

The vulnerability affects the Kimai time tracking application, specifically all versions prior to 2.57.0 as released by the Kimai project.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests exploitation is unlikely, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated and have editing rights for at least one parent object, and to submit a crafted request that points the rate ID to a record not owned by that parent. The vulnerability does not provide remote code execution or elevation of privilege, but it can lead to financial damage.

Generated by OpenCVE AI on September 17, 2026 at 17:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Kimai 2.57.0 or later to apply the vendor fix.
  • If an upgrade is delayed, restrict user permissions to disallow editing of parent objects or remove rate editing capabilities for non‑admin users until the fix is applied.
  • Audit existing rate configurations for inconsistencies and revert any unauthorized entries to their correct parent associations.

Generated by OpenCVE AI on September 17, 2026 at 17:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2xgg-2x8h-8xw4 Kimai: Improper Authorization in Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate Manipulation
History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Kimai
Kimai kimai
Vendors & Products Kimai
Kimai kimai

Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/{rate}, /en/admin/customer/{id}/rate/{rate}, and /en/admin/activity/{id}/rate/{rate} independently resolve the authorized parent identifier and the attacker-selected child rate identifier without confirming that the ProjectRate, CustomerRate, or ActivityRate belongs to that parent. An authenticated user who can edit one parent object can pair it with a rate record from an unauthorized project, customer, or activity and persist changes to billing configuration in kimai2_projects_rates, kimai2_customers_rates, or kimai2_activities_rates. This issue is fixed in version 2.57.0.
Title Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate Manipulation
Weaknesses CWE-285
CWE-639
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T12:41:20.164Z

Reserved: 2026-06-08T18:11:06.661Z

Link: CVE-2026-52826

cve-icon Vulnrichment

Updated: 2026-09-15T12:41:10.867Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:09.837

Modified: 2026-09-23T18:22:16.503

Link: CVE-2026-52826

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-639

    Authorization Bypass Through User-Controlled Key