Executive brief
Kimai, an open-source time-tracking application, contains a flaw that allows one user to modify another user's 'favorite' timesheet bookmarks. An attacker with a standard account can add or remove entries from a colleague's quick-access list if they know the ID of a timesheet. While this does not expose sensitive data, it allows for unauthorized tampering with a user's workflow and data organization.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in Kimai versions up to 2.56.0 within the FavoriteController. The endpoints `/en/favorite/timesheet/add/{id}` and `/en/favorite/timesheet/remove/{id}` fail to validate that the requested timesheet belongs to the authenticated user. The root cause is located in `FavoriteRecordService.php`, where the bookmark owner is incorrectly derived from the user associated with the timesheet object rather than the current session user. An authenticated attacker with `start_own_timesheet` permissions can exploit this to inject or delete entries in any victim's favorite/recent list. The issue is resolved in version 2.57.0.
Affected products
- Kimai Kimai <= 2.56.0
Timeline
- 2026-05-29: disclosed
- 2026-07-02: advisory
- 2026-07-02: patched: Fixed in version 2.57.0