Impact
A missing causes the create and edit actions to inherit only the class-level create_export permission, which the ROLE_TEAMLEAD role receives by default, and omit the required create_export_template permission required by the API routes and user interface. A teamlead can directly access the export template creation and editing web routes to create or modify global ExportTemplate records marked available to all users, altering export columns, renderer, format, and output used by other users and administrators. This flaw therefore represents an elevation of privilege that allows a privileged user to change system‑wide export behavior, compromising the confidentiality and integrity of exports.
Affected Systems
The vulnerability affects the Kimai time‑tracking application provided by kimai:kimai. All releases prior to version 2.58.0 are vulnerable; version 2.58.0 and later contain the fix.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score below 1% suggests the probability of exploitation is currently very low. The issue is not listed in the CISA KEV catalog. Exploitation requires authentication as a user with the TEAMLEAD role and access to the web interface; the vulnerability can therefore be leveraged remotely by any authenticated privileged user, which is inferred from the description of the web routes involved. The privilege escalation potential and the potential for widespread impact give the flaw a substantial risk to affected deployments.
OpenCVE Enrichment
Github GHSA