Junglewise Threat Intelligence

CVE-2026-84808: Kimai REST API timesheet authorization bypass in activity-team access controls

CVE-2026-84808 · Severity: medium · CVSS 4.3 · Published 2026-09-02

Technologies: Kimai. Vendors: Kimai.

Executive brief

Kimai is an open-source time-tracking application used by organizations to log and manage employee work hours. A flaw in the REST API allows users with basic access permissions to view timesheets from activities they should not have access to, bypassing team-based data isolation controls. This could expose sensitive timesheet data across team boundaries in multi-tenant environments.

Technical details

The vulnerability is an authorization bypass (CWE-863) in the GET /api/timesheets endpoint of Kimai's REST API. The TimesheetRepository's addPermissionCriteria() method checked project and customer team membership but failed to enforce activity-team access controls. A user with the view_other_timesheet permission (default for ROLE_TEAMLEAD) can list timesheets that use activities restricted to teams they do not belong to, whereas the single-entity GET /api/timesheets/{id} endpoint correctly enforces these restrictions. The attack requires authentication (view_other_timesheet permission) and network access to the API. The fix adds activity constraint validation to addPermissionCriteria(), patched in version 2.65.0.

Affected products

  • Kimai Kimai before 2.65.0

Timeline

  • 2026-08-19: disclosed: Security advisory published on GitHub
  • 2026-09-02: patched: Version 2.65.0 released with fix

References

Related threats