Impact
Kimai, an open‑source time tracking application, allows attackers to authenticate to the REST API by supplying only a valid password. During the period between password verification and TOTP completion, the KIMAI_SESSION cookie is accepted for all /api routes because the configuration protects the API with IS_AUTHENTICATED and the session is routed through the main firewall. The TwoFactorToken satisfies this rule, and the ApiVoter grants access to the user. Consequently an attacker with a legitimate account password can perform full API operations without providing the second factor, even though web routes still require TOTP. This flaw is an unrestricted API access that can lead to data exfiltration, manipulation, or escalation of privileges.
Affected Systems
All Kimai installations running any version prior to 2.59.0 are affected. The vulnerability is present in the kimai:kimai product and is mitigated only by upgrading to version 2.59.0 or later.
Risk and Exploitability
The CVSS score of 7.1 classifies the weakness as high severity. The EPSS score of less than 1% indicates that attacks against this flaw are currently considered unlikely, and it is not listed in CISA KEV catalog. The likely attack vector is network access to the REST API; an attacker must possess or steal a valid user password to exploit it. Once authenticated, the attacker can bypass the second factor and use any authorized API endpoint, potentially compromising data confidentiality and integrity.
OpenCVE Enrichment
Github GHSA