Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access Revocation (CVE-2026-52822)
Kimai 2.56.0 and earlier contain an authorization bypass vulnerability in the timesheet restart and duplicate workflows. After a user loses access to a project, they can still create new timesheets under that project by restarting or duplicating historical entries. This occurs because the authorization logic trusts ownership of old timesheets more than current project access rights, allowing persistent write access despite revocation. The issue affects API endpoints and the web UI flows that reuse historical project and activity bindings. This can lead to unauthorized time entries that undermine access control and affect project tracking and reporting.
AI Analysis
Technical Summary
Kimai versions prior to 2.58.0 have an authenticated authorization bypass in the timesheet restart and duplicate features. The vulnerability arises because the authorization logic prioritizes ownership of historical timesheets over current team-based access controls. Specifically, the restart and duplicate workflows copy project and activity data from old timesheets without verifying if the user still has access to those projects or activities. This allows users to create new timesheets under projects they no longer have permission to access. The root cause is that the authorization check in TimesheetVoter.php evaluates the user's ownership of the timesheet before checking team access, and the restart/duplicate capability only verifies object visibility, not current access rights. The issue affects PATCH API endpoints and the web UI, resulting in persistent unauthorized write access after project access revocation. The fix involves updating TimesheetVoter::canStart() to check team access for project and activity in all relevant workflows.
Potential Impact
Users who have had their access to a project revoked can still create new time entries for that project by restarting or duplicating old timesheets. This bypasses administrative access control changes and can lead to inaccurate project time tracking, budget calculations, statistics, reports, and invoicing. The vulnerability allows persistent unauthorized writes to the database, not just UI inconsistencies or caching issues. It undermines the integrity of project data and administrative controls.
Mitigation Recommendations
A fix is available in Kimai version 2.58.0 and later. The update modifies the authorization logic to verify team-based access to projects and activities during timesheet restart and duplicate operations. Users and administrators should upgrade to version 2.58.0 or later to remediate this vulnerability. Patch status is confirmed by the vendor advisory at https://www.kimai.org/en/security/ghsa-c6w6-57jj-62vh. No alternative mitigations are indicated.
Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access Revocation (CVE-2026-52822)
Description
Kimai 2.56.0 and earlier contain an authorization bypass vulnerability in the timesheet restart and duplicate workflows. After a user loses access to a project, they can still create new timesheets under that project by restarting or duplicating historical entries. This occurs because the authorization logic trusts ownership of old timesheets more than current project access rights, allowing persistent write access despite revocation. The issue affects API endpoints and the web UI flows that reuse historical project and activity bindings. This can lead to unauthorized time entries that undermine access control and affect project tracking and reporting.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Kimai versions prior to 2.58.0 have an authenticated authorization bypass in the timesheet restart and duplicate features. The vulnerability arises because the authorization logic prioritizes ownership of historical timesheets over current team-based access controls. Specifically, the restart and duplicate workflows copy project and activity data from old timesheets without verifying if the user still has access to those projects or activities. This allows users to create new timesheets under projects they no longer have permission to access. The root cause is that the authorization check in TimesheetVoter.php evaluates the user's ownership of the timesheet before checking team access, and the restart/duplicate capability only verifies object visibility, not current access rights. The issue affects PATCH API endpoints and the web UI, resulting in persistent unauthorized write access after project access revocation. The fix involves updating TimesheetVoter::canStart() to check team access for project and activity in all relevant workflows.
Potential Impact
Users who have had their access to a project revoked can still create new time entries for that project by restarting or duplicating old timesheets. This bypasses administrative access control changes and can lead to inaccurate project time tracking, budget calculations, statistics, reports, and invoicing. The vulnerability allows persistent unauthorized writes to the database, not just UI inconsistencies or caching issues. It undermines the integrity of project data and administrative controls.
Mitigation Recommendations
A fix is available in Kimai version 2.58.0 and later. The update modifies the authorization logic to verify team-based access to projects and activities during timesheet restart and duplicate operations. Users and administrators should upgrade to version 2.58.0 or later to remediate this vulnerability. Patch status is confirmed by the vendor advisory at https://www.kimai.org/en/security/ghsa-c6w6-57jj-62vh. No alternative mitigations are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-c6w6-57jj-62vh
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-52822"]
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a55ff8868715ace432f4651
Added to database: 07/14/2026, 09:21:12 UTC
Last enriched: 07/14/2026, 09:44:47 UTC
Last updated: 07/31/2026, 12:27:30 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.