top of page
perceptive_background_267k.jpg

Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timeshee…

Published:

26 augustus 2026 om 00:00:00

Alert date:

26 augustus 2026 om 18:17:38

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Identity & Access, Web Technologies

Kimai versions before 2.56.0 contain an authorization bypass vulnerability in TimesheetVoter::voteOnAttribute() that fails to enforce team-membership checks. The function maps permissions solely to own_timesheet or other_timesheet without verifying team relationships. Any authenticated user with ROLE_TEAMLEAD or roles granting edit_other_timesheet/delete_other_timesheet can read, modify, and permanently delete any user's timesheets system-wide via the API. Timesheet IDs are sequential integers, making enumeration trivial for attackers. ROLE_USER accounts are correctly restricted and not affected. The vulnerability was fixed in Kimai 2.56.0. The maintainers have noted this behavior aligns with their documented permission model, though it presents a significant access control risk in multi-team environments.

Technical details

Mitigation steps:

Affected products:

Kimai before 2.56.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page