Authorization Bypass in Kimai Timesheet Management by Kimai
CVE-2026-80202

9.3CRITICAL

Key Information:

Vendor

Kimai

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-80202?

The vulnerability in Kimai prior to version 2.56.0 allows authenticated users with specific roles, such as ROLE_TEAMLEAD, to bypass team membership checks in the Timesheet management system. This flaw enables such users to read, modify, and permanently delete timesheets of any user within the system via the API, regardless of their actual team affiliation. The sequential and easily enumerable nature of Timesheet IDs exacerbates this risk, as it makes it straightforward for users to access sensitive timesheet data. While ROLE_USER accounts are subject to proper restrictions, the oversight in permission enforcement poses a significant security concern.

Affected Version(s)

kimai 0 < 2.56.0

kimai 2.56.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nullvector1
.