Executive brief
Kimai is a time tracking and project management application used by teams to record work hours and manage billable activities. A flaw in its team access control system allows authenticated users with limited permissions to grant their team inappropriate access to customers, projects, or activities they should not be able to modify, potentially exposing sensitive project data and disrupting access control integrity.
Technical details
Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in team access endpoints. The vulnerable endpoints (POST /api/teams/{id}/customers/{customerId}, POST /api/teams/{id}/projects/{projectId}, POST /api/teams/{id}/activities/{activityId}) check only that the caller has edit permission on the team and view permission on the target entity, but fail to verify edit permission on the entity itself. An authenticated attacker with team edit permissions and read-only access to a customer, project, or activity can send POST requests to these endpoints to add that entity to a team's access control list, thereby granting unauthorized team access. The vulnerability requires authentication and network access to the API endpoints. The fix (version 2.63.0+) replaces the view permission check with a proper edit permission check for all entity types.
Affected products
- Kimai Kimai before 2.63.0
Timeline
- 2026-08-19: disclosed
- 2026-09-02: advisory
- 2026-09-02: patched: Version 2.63.0 released