Impact
The vulnerability in Kimai versions before 2.65.0 allows an authenticated user who has the edit_team permission to remove team access to activities, projects, and customers without performing the required permissions_activity check. This omission permits bypassing normal authorization controls, effectively granting elevated privileges to modify team resources. The weakness is an instance of improper authorization, classified as CWE‑284.
Affected Systems
All deployments of Kimai older than version 2.65.0 are affected; the flaw resides in the core API that handles removal of team access to activities, projects, and customers. No specific sub‑product or module is exempt.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS data is unavailable, so the exploitation probability cannot be quantified from the available information, and the vulnerability is not listed in the CISA KEV catalog. The attack requires an authenticated user with edit_team permission and involves calling the exposed API; no external engagement is needed beyond normal API usage. An attacker could elevate privileges or disrupt team access workflows until the vendor fix is applied.
OpenCVE Enrichment