SB2026081393 - Missing Authorization in kimai2
Published: August 13, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to create timesheets for team members.
The vulnerability exists due to missing authorization in the QuickEntry controller when handling QuickEntry form submissions for new rows. A remote user can submit the QuickEntry form with a duration for a new row to create timesheets for team members.
The issue is limited to users who are members of teams led by the attacking user, and exploitation requires the ability to view and edit other users\' timesheets.
Remediation
Install update from vendor's website.