CVE-2026-41498

LOW

Kimai: Team API Missing Object-Level Authorization

Title source: cna
STIX 2.1

Description

Kimai is an open-source time tracking application. Prior to version 2.54.0, the Team API endpoints use #[IsGranted('edit_team')] instead of #[IsGranted('edit', 'team')], causing Symfony TeamVoter to abstain from voting. This removes entity-level ownership checks on team operations, allowing any user with the edit_team permission to modify any team, not just teams they are authorized to manage. This issue has been patched in version 2.54.0.

References (2)

Core 2
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/kimai/kimai/releases/tag/2.54.0

Scores

CVSS v3 3.3
EPSS 0.0025
EPSS Percentile 15.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
kimai/kimai < 2.54.0 (2 CPE variants)
kimai/kimai 0 - 2.54.0Packagist
Published May 08, 2026
Tracked Since May 08, 2026