Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes (CVE-2026-49992)
Kimai version prior to 2.58.0 contains an authenticated cross-site request forgery (CSRF) vulnerability in default team creation endpoints accessed via GET requests. These endpoints allow unauthorized modification of team and permission structures by creating or reusing teams, assigning the victim user as teamlead, and binding projects, customers, or activities to those teams without explicit user consent. The vulnerability requires the victim to be logged in with permissions to manage the relevant object. The issue has been addressed by moving these routes to API POST endpoints.
AI Analysis
Technical Summary
Kimai 2.56.0 and earlier versions expose GET endpoints for default team creation shortcuts that perform persistent writes altering authorization structures. An attacker can exploit this authenticated CSRF vulnerability by tricking a logged-in user with appropriate permissions into visiting a malicious page, causing unauthorized creation or reuse of teams, assignment of the victim as teamlead, and binding of projects, customers, or activities to those teams. This modifies the authorization topology, impacting visibility, assignment scope, team-based access control, reporting, and potential privilege escalation. The vulnerability affects the routes GET /en/admin/project/{id}/create_team, GET /en/admin/customer/{id}/create_team, and GET /en/admin/activity/{id}/create_team. The issue is fixed by moving these endpoints to API POST methods in versions 2.58.0 and later.
Potential Impact
An attacker can remotely alter the authorization structure within Kimai by exploiting this CSRF vulnerability, causing unauthorized changes to teams and permission assignments. This can affect visibility rules, assignment scopes, team-based access control, and reporting, potentially enabling privilege escalation chains. The exploit requires the victim to be logged in with permission to manage the targeted project, customer, or activity. The impact is more severe than a typical CSRF affecting only UI preferences because it changes authorization topology.
Mitigation Recommendations
Upgrade Kimai to version 2.58.0 or later where the vulnerable GET endpoints have been replaced with API POST endpoints, mitigating the CSRF risk. No additional mitigation is required if the system is updated. Patch status is confirmed by the vendor advisory at https://www.kimai.org/en/security/ghsa-pgcc-vfmc-7cw5.
Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes (CVE-2026-49992)
Description
Kimai version prior to 2.58.0 contains an authenticated cross-site request forgery (CSRF) vulnerability in default team creation endpoints accessed via GET requests. These endpoints allow unauthorized modification of team and permission structures by creating or reusing teams, assigning the victim user as teamlead, and binding projects, customers, or activities to those teams without explicit user consent. The vulnerability requires the victim to be logged in with permissions to manage the relevant object. The issue has been addressed by moving these routes to API POST endpoints.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Kimai 2.56.0 and earlier versions expose GET endpoints for default team creation shortcuts that perform persistent writes altering authorization structures. An attacker can exploit this authenticated CSRF vulnerability by tricking a logged-in user with appropriate permissions into visiting a malicious page, causing unauthorized creation or reuse of teams, assignment of the victim as teamlead, and binding of projects, customers, or activities to those teams. This modifies the authorization topology, impacting visibility, assignment scope, team-based access control, reporting, and potential privilege escalation. The vulnerability affects the routes GET /en/admin/project/{id}/create_team, GET /en/admin/customer/{id}/create_team, and GET /en/admin/activity/{id}/create_team. The issue is fixed by moving these endpoints to API POST methods in versions 2.58.0 and later.
Potential Impact
An attacker can remotely alter the authorization structure within Kimai by exploiting this CSRF vulnerability, causing unauthorized changes to teams and permission assignments. This can affect visibility rules, assignment scopes, team-based access control, and reporting, potentially enabling privilege escalation chains. The exploit requires the victim to be logged in with permission to manage the targeted project, customer, or activity. The impact is more severe than a typical CSRF affecting only UI preferences because it changes authorization topology.
Mitigation Recommendations
Upgrade Kimai to version 2.58.0 or later where the vulnerable GET endpoints have been replaced with API POST endpoints, mitigating the CSRF risk. No additional mitigation is required if the system is updated. Patch status is confirmed by the vendor advisory at https://www.kimai.org/en/security/ghsa-pgcc-vfmc-7cw5.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-pgcc-vfmc-7cw5
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-49992"]
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a55ff8968715ace432f46da
Added to database: 07/14/2026, 09:21:13 UTC
Last enriched: 07/14/2026, 09:45:20 UTC
Last updated: 07/31/2026, 12:27:30 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.