Kimai: Login CSRF in the Timesheet Stop and Restart API Endpoints Allows Unauthorized State Changes (CVE-2026-52823)
Kimai 2.56.0 and earlier versions contain an authenticated cross-site request forgery (CSRF) vulnerability in the timesheet stop and restart API endpoints. The application exposes state-changing operations via GET requests, which should be read-only, allowing attackers to trick logged-in users into triggering unauthorized timesheet state changes. This can stop running timesheets or restart historical ones without user consent, potentially corrupting time tracking data and affecting billing or auditing processes. The issue is fixed by removing the GET routes and limiting these operations to PATCH requests only.
AI Analysis
Technical Summary
Kimai versions prior to 2.58.0 have a CSRF vulnerability in the timesheet API where the stop and restart operations are accessible via GET requests that modify business state. Since these endpoints reuse the browser's existing session and do not require additional user interaction, an attacker can cause unauthorized state changes by tricking an authenticated user into visiting a malicious page. The vulnerability affects the GET /api/timesheets/{id}/stop and GET /api/timesheets/{id}/restart routes. The fix involves removing these GET routes and restricting the operations to PATCH methods only.
Potential Impact
An attacker can cause unauthorized changes to timesheet states for authenticated users without their consent. This can stop active timesheets or restart historical ones, leading to corrupted time records, inaccurate billing, distorted reporting, and interference with approval or audit processes. The attack requires only that the victim be logged in and visit a malicious page, making the attack vector low barrier. There are persistent side effects on the database and business logic integrity.
Mitigation Recommendations
The vulnerability is addressed by removing the GET routes for stop and restart operations and allowing these actions only via PATCH requests. Users should upgrade to Kimai version 2.58.0 or later where this fix is implemented. No additional mitigations are specified by the vendor advisory.
Kimai: Login CSRF in the Timesheet Stop and Restart API Endpoints Allows Unauthorized State Changes (CVE-2026-52823)
Description
Kimai 2.56.0 and earlier versions contain an authenticated cross-site request forgery (CSRF) vulnerability in the timesheet stop and restart API endpoints. The application exposes state-changing operations via GET requests, which should be read-only, allowing attackers to trick logged-in users into triggering unauthorized timesheet state changes. This can stop running timesheets or restart historical ones without user consent, potentially corrupting time tracking data and affecting billing or auditing processes. The issue is fixed by removing the GET routes and limiting these operations to PATCH requests only.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Kimai versions prior to 2.58.0 have a CSRF vulnerability in the timesheet API where the stop and restart operations are accessible via GET requests that modify business state. Since these endpoints reuse the browser's existing session and do not require additional user interaction, an attacker can cause unauthorized state changes by tricking an authenticated user into visiting a malicious page. The vulnerability affects the GET /api/timesheets/{id}/stop and GET /api/timesheets/{id}/restart routes. The fix involves removing these GET routes and restricting the operations to PATCH methods only.
Potential Impact
An attacker can cause unauthorized changes to timesheet states for authenticated users without their consent. This can stop active timesheets or restart historical ones, leading to corrupted time records, inaccurate billing, distorted reporting, and interference with approval or audit processes. The attack requires only that the victim be logged in and visit a malicious page, making the attack vector low barrier. There are persistent side effects on the database and business logic integrity.
Mitigation Recommendations
The vulnerability is addressed by removing the GET routes for stop and restart operations and allowing these actions only via PATCH requests. Users should upgrade to Kimai version 2.58.0 or later where this fix is implemented. No additional mitigations are specified by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-r8vr-m544-qh4h
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-52823"]
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a55ff8868715ace432f464d
Added to database: 07/14/2026, 09:21:12 UTC
Last enriched: 07/14/2026, 09:44:34 UTC
Last updated: 07/31/2026, 12:27:30 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.