{"id":"CVE-2026-41498","aliases":["GHSA-jv9x-w4gm-hwcm"],"url":"https://o3.security/vulnerability/CVE-2026-41498","summary":"Kimai: Team API Missing Object-Level Authorization","details":"Kimai is an open-source time tracking application. Prior to version 2.54.0, the Team API endpoints use #[IsGranted('edit_team')] instead of #[IsGranted('edit', 'team')], causing Symfony TeamVoter to abstain from voting. This removes entity-level ownership checks on team operations, allowing any user with the edit_team permission to modify any team, not just teams they are authorized to manage. This issue has been patched in version 2.54.0.","published":"2026-05-08T03:30:32.310Z","modified":"2026-08-05T03:47:31.453127008Z","cvss":{"score":3.3,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"kimai/kimai","fixedVersion":"2.54.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/kimai/kimai/releases/tag/2.54.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41498.json"},{"type":"ADVISORY","url":"https://github.com/kimai/kimai/security/advisories/GHSA-jv9x-w4gm-hwcm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41498"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-05T03:47:31.453127008Z"}}