PT-2026-81910 · Kimai · Kimai

·

CVE-2026-80197

·

Published

2026-07-02

·

Updated

2026-08-26

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kimai versions prior to 2.57.0
Description An improper authorization issue exists in the endpoints used to add and remove favorite timesheets. This allows authenticated users to manipulate bookmarks belonging to other users by referencing a specific timesheet identifier, resulting in cross-user business-state tampering without requiring administrative privileges.
Recommendations Update to version 2.57.0 or later.

Exploit

Fix

IDOR

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80197
GHSA-J5MC-P8QG-39J7

Affected Products

Kimai