Improper Authorization Vulnerability in Kimai Product by Kimai
CVE-2026-80197
8.7HIGH
What is CVE-2026-80197?
Kimai prior to version 2.57.0 has a security flaw involving improper authorization in its favorite timesheet functionalities. This vulnerability allows authenticated users to interfere with other users' bookmark settings by using their respective timesheet identifiers. Consequently, attackers can add or remove timesheet entries from another user's favorites list without requiring administrative permissions, leading to potential cross-user tampering of business states.
Affected Version(s)
kimai 0 < 2.57.0
kimai 2.57.0
