CVE-2026-41498: Kimai: Team API Missing Object-Level Authorization
Summary The Team API endpoints use #[IsGranted('editteam')] instead of #[IsGranted('edit', 'team')], causing Symfony TeamVoter to abstain from voting. This removes entity-level ownership checks on team operations, allowing any user with the editteam permission to modify any team, not just teams they are authorized to manage.
Details All 8 team association endpoints in src/API/TeamController.php (lines 177, 201, 229, 252, 275, 298, 321, 339) use #[IsGranted('editteam')] with a single argument. The web controller at src/Controller/TeamController.php:118 correctly uses #[IsGranted('edit', 'team')] with two arguments, passing the $team parameter as the subject. When editteam is passed as the attribute, TeamVoter::supportsAttribute() returns false because it only recognizes view, edit, and delete. The voter abstains entirely. Only RolePermissionVoter fires, which checks the role-level permission without any entity-level ownership validation.
PoC Authenticate as a user with editteam permission who is NOT a member of Team 1 curl -X POST https://TARGET/api/teams/1/members/2 \ -H "Authorization: Bearer <APITOKEN>" \ -H "Content-Type: application/json"
Expected: 403 Forbidden (user is not ROLEADMIN/ROLESUPERADMIN, or member of Team 1) Actual (pre-2.54.0): 200 OK, user added to Team 1
Impact In default configuration, only ROLEADMIN and ROLESUPERADMIN have editteam, and both roles already have irrevocable viewalldata access, making the missing check redundant. The vulnerability becomes exploitable if an administrator grants editteam to a lower-privilege role (such as ROLETEAMLEAD) through the permissions UI. In that scenario, the lower-privilege user could modify any team's membership, customer assignments, project assignments, and activity assignments without being a member or teamlead of that team.
Other sources
Kimai is an open-source time tracking application. Prior to version 2.54.0, the Team API endpoints use #[IsGranted('editteam')] instead of #[IsGranted('edit', 'team')], causing Symfony TeamVoter to abstain from voting. This removes entity-level ownership checks on team operations, allowing any user with the editteam permission to modify any team, not just teams they are authorized to manage. This issue has been patched in version 2.54.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41498?
CVE-2026-41498 has a high severity due to its potential to allow unauthorized users to modify teams.
How do I fix CVE-2026-41498?
To fix CVE-2026-41498, update the kimai/kimai package to version 2.54.0 or later.
What systems are affected by CVE-2026-41498?
CVE-2026-41498 affects versions of the kimai/kimai package prior to 2.54.0.
What type of vulnerability is CVE-2026-41498?
CVE-2026-41498 is an access control vulnerability that allows improper permissions to modify team data.
Who is exposed to CVE-2026-41498?
Any user with the edit_team permission is exposed to CVE-2026-41498, potentially leading to unauthorized modifications of teams.