Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access Revocation (CVE-2026-52822)

0
Medium
Published: 07/14/2026 (07/14/2026, 00:04:26 UTC)
Source: GCVE Database
Product: kimai/kimai

Description

Kimai 2.56.0 and earlier contain an authorization bypass vulnerability in the timesheet restart and duplicate workflows. After a user loses access to a project, they can still create new timesheets under that project by restarting or duplicating historical entries. This occurs because the authorization logic trusts ownership of old timesheets more than current project access rights, allowing persistent write access despite revocation. The issue affects API endpoints and the web UI flows that reuse historical project and activity bindings. This can lead to unauthorized time entries that undermine access control and affect project tracking and reporting.

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
Low
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected software

Packagistghsa
kimai/kimai
Affected versions
<2.58.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/14/2026, 09:44:47 UTC

Technical Analysis

Kimai versions prior to 2.58.0 have an authenticated authorization bypass in the timesheet restart and duplicate features. The vulnerability arises because the authorization logic prioritizes ownership of historical timesheets over current team-based access controls. Specifically, the restart and duplicate workflows copy project and activity data from old timesheets without verifying if the user still has access to those projects or activities. This allows users to create new timesheets under projects they no longer have permission to access. The root cause is that the authorization check in TimesheetVoter.php evaluates the user's ownership of the timesheet before checking team access, and the restart/duplicate capability only verifies object visibility, not current access rights. The issue affects PATCH API endpoints and the web UI, resulting in persistent unauthorized write access after project access revocation. The fix involves updating TimesheetVoter::canStart() to check team access for project and activity in all relevant workflows.

Potential Impact

Users who have had their access to a project revoked can still create new time entries for that project by restarting or duplicating old timesheets. This bypasses administrative access control changes and can lead to inaccurate project time tracking, budget calculations, statistics, reports, and invoicing. The vulnerability allows persistent unauthorized writes to the database, not just UI inconsistencies or caching issues. It undermines the integrity of project data and administrative controls.

Mitigation Recommendations

A fix is available in Kimai version 2.58.0 and later. The update modifies the authorization logic to verify team-based access to projects and activities during timesheet restart and duplicate operations. Users and administrators should upgrade to version 2.58.0 or later to remediate this vulnerability. Patch status is confirmed by the vendor advisory at https://www.kimai.org/en/security/ghsa-c6w6-57jj-62vh. No alternative mitigations are indicated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-c6w6-57jj-62vh
Osv Schema Version
1.4.0
Aliases
["CVE-2026-52822"]
Ecosystems
["Packagist"]
Database Specific Severity
MODERATE
Cvss Version
4.0

Threat ID: 6a55ff8868715ace432f4651

Added to database: 07/14/2026, 09:21:12 UTC

Last enriched: 07/14/2026, 09:44:47 UTC

Last updated: 07/31/2026, 12:27:30 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses