PT-2026-81915 · Kimai · Kimai

·

CVE-2026-80202

·

Published

2026-05-06

·

Updated

2026-09-03

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kimai versions prior to 2.56.0
Description An issue exists where team-membership checks are not enforced in the voteOnAttribute() function of TimesheetVoter. This function maps permissions only to own timesheet or other timesheet. Consequently, any authenticated user with ROLE TEAMLEAD or a role possessing edit other timesheet or delete other timesheet permissions can read, modify, and permanently delete timesheets of any user across the entire system via the API, regardless of whether they belong to the same team. This is facilitated by the fact that timesheet IDs are sequential integers and easily enumerable.
Recommendations Update to version 2.56.0 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80202
GHSA-9G2Q-W3W2-VF7Q

Affected Products

Kimai