Description
Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportController::editExportTemplate() inherit only the class-level create_export permission, which ROLE_TEAMLEAD receives by default, and omit the create_export_template permission required by the API routes and user interface. A teamlead can directly access the export template creation and editing web routes to create or modify global ExportTemplate records marked available to all users, altering export columns, renderer, format, and output used by other users and administrators. This issue is fixed in version 2.58.0.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Unchecked Authorization
Action: Upgrade
AI Analysis

Impact

A missing causes the create and edit actions to inherit only the class-level create_export permission, which the ROLE_TEAMLEAD role receives by default, and omit the required create_export_template permission required by the API routes and user interface. A teamlead can directly access the export template creation and editing web routes to create or modify global ExportTemplate records marked available to all users, altering export columns, renderer, format, and output used by other users and administrators. This flaw therefore represents an elevation of privilege that allows a privileged user to change system‑wide export behavior, compromising the confidentiality and integrity of exports.

Affected Systems

The vulnerability affects the Kimai time‑tracking application provided by kimai:kimai. All releases prior to version 2.58.0 are vulnerable; version 2.58.0 and later contain the fix.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score below 1% suggests the probability of exploitation is currently very low. The issue is not listed in the CISA KEV catalog. Exploitation requires authentication as a user with the TEAMLEAD role and access to the web interface; the vulnerability can therefore be leveraged remotely by any authenticated privileged user, which is inferred from the description of the web routes involved. The privilege escalation potential and the potential for widespread impact give the flaw a substantial risk to affected deployments.

Generated by OpenCVE AI on September 17, 2026 at 17:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Kimai 2.58.0 patch or any later release that includes the authorization fix
  • If an immediate patch is not feasible, temporarily restrict or remove the TEAMLEAD role from untrusted users and ensure no other users except trusted admins retain the ability to create or edit global export templates
  • Enable monitoring of ExportTemplate creation and modification logs to detect unauthorized changes, and validate that users with the create_export_template permission are the only ones performing those actions
  • Review and reinforce the application’s role‑based access controls to prevent similar authorization bypasses in future changes

Generated by OpenCVE AI on September 17, 2026 at 17:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-rw46-qg69-vg6h Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access
History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Kimai
Kimai kimai
Vendors & Products Kimai
Kimai kimai

Tue, 15 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportController::editExportTemplate() inherit only the class-level create_export permission, which ROLE_TEAMLEAD receives by default, and omit the create_export_template permission required by the API routes and user interface. A teamlead can directly access the export template creation and editing web routes to create or modify global ExportTemplate records marked available to all users, altering export columns, renderer, format, and output used by other users and administrators. This issue is fixed in version 2.58.0.
Title Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T12:29:14.797Z

Reserved: 2026-06-08T18:11:06.662Z

Link: CVE-2026-52828

cve-icon Vulnrichment

Updated: 2026-09-15T12:29:05.164Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:10.147

Modified: 2026-09-23T18:22:16.503

Link: CVE-2026-52828

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses