Missing Authorization in kimai2 - CVE-2026-80193
Published: August 13, 2026 / Updated: September 14, 2026
Vulnerability details
The vulnerability allows a remote user to create timesheets for team members.
The vulnerability exists due to missing authorization in the QuickEntry controller when handling QuickEntry form submissions for new rows. A remote user can submit the QuickEntry form with a duration for a new row to create timesheets for team members.
The issue is limited to users who are members of teams led by the attacking user, and exploitation requires the ability to view and edit other users\' timesheets.