Authorization bypass through user-controlled key in kimai2 - CVE-2026-80197

 

Authorization bypass through user-controlled key in kimai2 - CVE-2026-80197

Published: June 29, 2026 / Updated: September 14, 2026


Vulnerability identifier: #VU135841
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80197
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to manipulate another user's favorite bookmark state.

The vulnerability exists due to improper authorization in the favorite timesheet add and remove endpoints when handling user-controlled timesheet identifiers. A remote user can send crafted requests referencing another user's timesheet ID to manipulate another user's favorite bookmark state.

The affected endpoints do not verify that the referenced timesheet belongs to the current session user, and the bookmark owner is derived from the referenced timesheet object instead of the authenticated user.


Affected software

kimai2

How to mitigate CVE-2026-80197

Install security update from vendor's website.

kimai2 - update to 2.57.0

External References

Related Security Bulletins