Kimai · Kimai · CVE-2026-80193
**Name of the Vulnerable Software and Affected Versions**
Kimai versions prior to 2.62.0
**Description**
An authorization bypass exists in the `QuickEntry` controller during the creation of new timesheets. Authenticated users who possess `view other timesheet` and `edit other timesheet` permissions can create timesheet records for other team members by submitting the QuickEntry form, as the system fails to validate the `create other timesheet` permission.
**Recommendations**
Update to version 2.62.0 or later.