CVE-2026-41498: Kimai: Team API Missing Object-Level Authorization

Published Apr 24, 2026
·
Updated

Summary The Team API endpoints use #[IsGranted('editteam')] instead of #[IsGranted('edit', 'team')], causing Symfony TeamVoter to abstain from voting. This removes entity-level ownership checks on team operations, allowing any user with the editteam permission to modify any team, not just teams they are authorized to manage.

Details All 8 team association endpoints in src/API/TeamController.php (lines 177, 201, 229, 252, 275, 298, 321, 339) use #[IsGranted('editteam')] with a single argument. The web controller at src/Controller/TeamController.php:118 correctly uses #[IsGranted('edit', 'team')] with two arguments, passing the $team parameter as the subject. When editteam is passed as the attribute, TeamVoter::supportsAttribute() returns false because it only recognizes view, edit, and delete. The voter abstains entirely. Only RolePermissionVoter fires, which checks the role-level permission without any entity-level ownership validation.

PoC Authenticate as a user with editteam permission who is NOT a member of Team 1 curl -X POST https://TARGET/api/teams/1/members/2 \ -H "Authorization: Bearer <APITOKEN>" \ -H "Content-Type: application/json"

Expected: 403 Forbidden (user is not ROLEADMIN/ROLESUPERADMIN, or member of Team 1) Actual (pre-2.54.0): 200 OK, user added to Team 1

Impact In default configuration, only ROLEADMIN and ROLESUPERADMIN have editteam, and both roles already have irrevocable viewalldata access, making the missing check redundant. The vulnerability becomes exploitable if an administrator grants editteam to a lower-privilege role (such as ROLETEAMLEAD) through the permissions UI. In that scenario, the lower-privilege user could modify any team's membership, customer assignments, project assignments, and activity assignments without being a member or teamlead of that team.

Other sources

Kimai is an open-source time tracking application. Prior to version 2.54.0, the Team API endpoints use #[IsGranted('editteam')] instead of #[IsGranted('edit', 'team')], causing Symfony TeamVoter to abstain from voting. This removes entity-level ownership checks on team operations, allowing any user with the editteam permission to modify any team, not just teams they are authorized to manage. This issue has been patched in version 2.54.0.

MITRE

Affected Software

2 affected componentsFixes available
composer/kimai/kimai<2.54.0
2.54.0
Kimai Kimai<2.54.0

Event History

Apr 24, 2026
Advisory Published
via GitHub·04:17 PM
Data Sourced
via GitHub·04:17 PM
DescriptionSeverityWeaknessAffected Software
May 8, 2026
CVE Published
via MITRE·03:30 AM
Data Sourced
via MITRE·03:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-41498?

CVE-2026-41498 has a high severity due to its potential to allow unauthorized users to modify teams.

2

How do I fix CVE-2026-41498?

To fix CVE-2026-41498, update the kimai/kimai package to version 2.54.0 or later.

3

What systems are affected by CVE-2026-41498?

CVE-2026-41498 affects versions of the kimai/kimai package prior to 2.54.0.

4

What type of vulnerability is CVE-2026-41498?

CVE-2026-41498 is an access control vulnerability that allows improper permissions to modify team data.

5

Who is exposed to CVE-2026-41498?

Any user with the edit_team permission is exposed to CVE-2026-41498, potentially leading to unauthorized modifications of teams.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203