Executive brief
Kimai is an open-source time-tracking application used by organizations to log and manage employee work hours. A flaw in the REST API allows users with basic access permissions to view timesheets from activities they should not have access to, bypassing team-based data isolation controls. This could expose sensitive timesheet data across team boundaries in multi-tenant environments.
Technical details
The vulnerability is an authorization bypass (CWE-863) in the GET /api/timesheets endpoint of Kimai's REST API. The TimesheetRepository's addPermissionCriteria() method checked project and customer team membership but failed to enforce activity-team access controls. A user with the view_other_timesheet permission (default for ROLE_TEAMLEAD) can list timesheets that use activities restricted to teams they do not belong to, whereas the single-entity GET /api/timesheets/{id} endpoint correctly enforces these restrictions. The attack requires authentication (view_other_timesheet permission) and network access to the API. The fix adds activity constraint validation to addPermissionCriteria(), patched in version 2.65.0.
Affected products
- Kimai Kimai before 2.65.0
Timeline
- 2026-08-19: disclosed: Security advisory published on GitHub
- 2026-09-02: patched: Version 2.65.0 released with fix