Impact
Kimai versions prior to 2.65.0 allow an authenticated user who has project permission‑management privileges to create a team that shares the name of an existing team via the team creation endpoints. The API then reuses the existing team and assigns the calling user as the team lead without checking that the user is allowed to manage that team. The result is that the attacker obtains administrative control over an existing team, enabling them to oversee or manipulate all data associated with that team. The weakness is classified as CWE-266, an improper privilege management vulnerability.
Affected Systems
All installations of Kimai (kimai/kimai) before version 2.65.0 are vulnerable. The vulnerability is present in the default team creation endpoints for customers, projects, and activities.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker first authenticate to the system and possess project permission‑management privileges; thus the attack vector is likely internal or requires prior compromise of an authorized account.
OpenCVE Enrichment