Description
Kimai is an open-source time tracking application. Prior to version 2.54.0, the Team API endpoints use #[IsGranted('edit_team')] instead of #[IsGranted('edit', 'team')], causing Symfony TeamVoter to abstain from voting. This removes entity-level ownership checks on team operations, allowing any user with the edit_team permission to modify any team, not just teams they are authorized to manage. This issue has been patched in version 2.54.0.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/kimai/kimai/security/advisories/GHSA-jv9x-w4gm-hwcm
X_Refsource_Misc x_refsource_misc
https://github.com/kimai/kimai/releases/tag/2.54.0
Scores
CVSS v3
3.3
EPSS
0.0025
EPSS Percentile
15.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (2)
kimai/kimai
< 2.54.0 (2 CPE variants)
kimai/kimai
0 - 2.54.0Packagist
Published
May 08, 2026
Tracked Since
May 08, 2026