PT-2026-81906 · Kimai · Kimai

·

CVE-2026-80193

·

Published

2026-08-25

·

Updated

2026-08-26

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kimai versions prior to 2.62.0
Description An authorization bypass exists in the QuickEntry controller during the creation of new timesheets. Authenticated users who possess view other timesheet and edit other timesheet permissions can create timesheet records for other team members by submitting the QuickEntry form, as the system fails to validate the create other timesheet permission.
Recommendations Update to version 2.62.0 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80193
GHSA-2W7F-X78F-89Q2

Affected Products

Kimai