Authorization Bypass in Kimai Timesheet Management by Kimai
CVE-2026-80202
9.3CRITICAL
What is CVE-2026-80202?
The vulnerability in Kimai prior to version 2.56.0 allows authenticated users with specific roles, such as ROLE_TEAMLEAD, to bypass team membership checks in the Timesheet management system. This flaw enables such users to read, modify, and permanently delete timesheets of any user within the system via the API, regardless of their actual team affiliation. The sequential and easily enumerable nature of Timesheet IDs exacerbates this risk, as it makes it straightforward for users to access sensitive timesheet data. While ROLE_USER accounts are subject to proper restrictions, the oversight in permission enforcement poses a significant security concern.
Affected Version(s)
kimai 0 < 2.56.0
kimai 2.56.0
