Junglewise Threat Intelligence

CVE-2026-49992: Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their

CVE-2026-49992 · Severity: medium · CVSS 4 · Published 2026-09-11

Technologies: kimai/kimai (Packagist), Kimai. Vendors: Packagist, Kimai.

Executive brief

Kimai, an open-source time-tracking application, contains a security flaw that allows unauthorized changes to team and permission structures. By tricking a logged-in administrator into clicking a malicious link, an attacker can force the system to create new teams or reassign project ownership. This could lead to unauthorized access to sensitive project data, reporting errors, and a breakdown of organizational access controls.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in Kimai versions up to 2.57.0 due to the use of GET requests for state-changing operations. Specifically, the endpoints for creating teams for projects, customers, and activities (/en/admin/project/{id}/create_team, etc.) perform persistent writes without proper CSRF protection. An attacker can exploit this by inducing an authenticated user with management permissions to visit a malicious URL. Successful exploitation allows the attacker to create or reuse teams, assign the victim as a team lead, and bind objects to those teams, effectively altering the application's authorization topology. The issue was resolved in version 2.58.0 by migrating these routes to POST endpoints.

Affected products

  • Kimai Kimai <= 2.57.0

Timeline

  • 2026-06-03: disclosed: Initial disclosure to GitHub Advisory Database
  • 2026-07-13: advisory: GitHub Advisory published and reviewed
  • 2026-07-13: patched: Fix confirmed in version 2.58.0

References

Related threats