Authorization Bypass in Kimai Affects QuickEntry Feature
CVE-2026-80193

8.7HIGH

Key Information:

Vendor

Kimai

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-80193?

The affected version of Kimai fails to properly validate permissions in the QuickEntry controller, allowing authenticated users with certain permissions to create unauthorized timesheet records for other users. This vulnerability means that users who should only have view and edit permissions can exploit this flaw, leading to potential misuse of timesheet data. It's critical for Kimai users to upgrade to version 2.62.0 or later to mitigate this issue.

Affected Version(s)

kimai 0 < 2.62.0

kimai 2.62.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xTodor
kevinpapst
.