SB2026081393 - Missing Authorization in kimai2



SB2026081393 - Missing Authorization in kimai2

Published: August 13, 2026

Security Bulletin ID SB2026081393
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to create timesheets for team members.

The vulnerability exists due to missing authorization in the QuickEntry controller when handling QuickEntry form submissions for new rows. A remote user can submit the QuickEntry form with a duration for a new row to create timesheets for team members.

The issue is limited to users who are members of teams led by the attacking user, and exploitation requires the ability to view and edit other users\' timesheets.


Remediation

Install update from vendor's website.