Junglewise Threat Intelligence

Kimai IDOR in favorite timesheet add and remove endpoints

Severity: low · CVSS 1.3 · Published 2026-07-02

Technologies: kimai/kimai (Packagist), Kimai. Vendors: Packagist, Kimai.

Executive brief

Kimai, an open-source time-tracking application, contains a flaw that allows one user to modify another user's 'favorite' timesheet bookmarks. An attacker with a standard account can add or remove entries from a colleague's quick-access list if they know the ID of a timesheet. While this does not expose sensitive data, it allows for unauthorized tampering with a user's workflow and data organization.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in Kimai versions up to 2.56.0 within the FavoriteController. The endpoints `/en/favorite/timesheet/add/{id}` and `/en/favorite/timesheet/remove/{id}` fail to validate that the requested timesheet belongs to the authenticated user. The root cause is located in `FavoriteRecordService.php`, where the bookmark owner is incorrectly derived from the user associated with the timesheet object rather than the current session user. An authenticated attacker with `start_own_timesheet` permissions can exploit this to inject or delete entries in any victim's favorite/recent list. The issue is resolved in version 2.57.0.

Affected products

  • Kimai Kimai <= 2.56.0

Timeline

  • 2026-05-29: disclosed
  • 2026-07-02: advisory
  • 2026-07-02: patched: Fixed in version 2.57.0

References

Related threats