Impact
Kimai versions earlier than 2.65.0 contain an authorization bypass in the REST API timesheet collection endpoint. The bug causes the system to ignore team‑based access restrictions for activities, allowing a user who possesses the view_other_timesheet permission to list timesheets that belong to activities of teams the user is not a member of. This flaw enables an attacker to exfiltrate confidential timesheet data that should be protected by team boundaries, leading to a breach of confidentiality.
Affected Systems
The affected is the Kimai time‑tracking application. All instances running a Kimai version prior to 2.65.0 are vulnerable, regardless of deployment environment. Versions 2.65.0 and later include the fix and are not affected.
Risk and Exploitability
The flaw scores a CVSS of 5.3, indicating moderate impact. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need network access to the Kimai REST API. Based on the description, the likely attack vector is remote exploitation of the API by sending crafted requests that include a valid view_other_timesheet token. Once accessed, the attacker can gather timesheet data from unauthorized teams, compromising sensitive business information.
OpenCVE Enrichment