Incorrect authorization in kimai2 - #VU144257
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the GET /api/timesheets endpoint when listing timesheet records via the REST API. A remote user can send a request to list timesheets belonging to other users to disclose sensitive information.
Exploitation requires the view_other_timesheet permission and installations that use team-restricted activities.