Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Kimai: Login CSRF in the Timesheet Stop and Restart API Endpoints Allows Unauthorized State Changes (CVE-2026-52823)

0
Medium
Published: 07/14/2026 (07/14/2026, 00:05:04 UTC)
Source: GCVE Database
Product: kimai/kimai

Description

Kimai 2.56.0 and earlier versions contain an authenticated cross-site request forgery (CSRF) vulnerability in the timesheet stop and restart API endpoints. The application exposes state-changing operations via GET requests, which should be read-only, allowing attackers to trick logged-in users into triggering unauthorized timesheet state changes. This can stop running timesheets or restart historical ones without user consent, potentially corrupting time tracking data and affecting billing or auditing processes. The issue is fixed by removing the GET routes and limiting these operations to PATCH requests only.

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
Low
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected software

Packagistghsa
kimai/kimai
Affected versions
<2.58.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/14/2026, 09:44:34 UTC

Technical Analysis

Kimai versions prior to 2.58.0 have a CSRF vulnerability in the timesheet API where the stop and restart operations are accessible via GET requests that modify business state. Since these endpoints reuse the browser's existing session and do not require additional user interaction, an attacker can cause unauthorized state changes by tricking an authenticated user into visiting a malicious page. The vulnerability affects the GET /api/timesheets/{id}/stop and GET /api/timesheets/{id}/restart routes. The fix involves removing these GET routes and restricting the operations to PATCH methods only.

Potential Impact

An attacker can cause unauthorized changes to timesheet states for authenticated users without their consent. This can stop active timesheets or restart historical ones, leading to corrupted time records, inaccurate billing, distorted reporting, and interference with approval or audit processes. The attack requires only that the victim be logged in and visit a malicious page, making the attack vector low barrier. There are persistent side effects on the database and business logic integrity.

Mitigation Recommendations

The vulnerability is addressed by removing the GET routes for stop and restart operations and allowing these actions only via PATCH requests. Users should upgrade to Kimai version 2.58.0 or later where this fix is implemented. No additional mitigations are specified by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-r8vr-m544-qh4h
Osv Schema Version
1.4.0
Aliases
["CVE-2026-52823"]
Ecosystems
["Packagist"]
Database Specific Severity
MODERATE
Cvss Version
4.0

Threat ID: 6a55ff8868715ace432f464d

Added to database: 07/14/2026, 09:21:12 UTC

Last enriched: 07/14/2026, 09:44:34 UTC

Last updated: 07/31/2026, 12:27:30 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses