Missing Authorization in kimai2 - CVE-2026-80193

 

Missing Authorization in kimai2 - CVE-2026-80193

Published: August 13, 2026 / Updated: September 14, 2026


Vulnerability identifier: #VU142429
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80193
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to create timesheets for team members.

The vulnerability exists due to missing authorization in the QuickEntry controller when handling QuickEntry form submissions for new rows. A remote user can submit the QuickEntry form with a duration for a new row to create timesheets for team members.

The issue is limited to users who are members of teams led by the attacking user, and exploitation requires the ability to view and edit other users\' timesheets.


Affected software

kimai2

How to mitigate CVE-2026-80193

Install security update from vendor's website.

kimai2 - update to 2.62.0

External References

Related Security Bulletins