PatchSiren cyber security CVE debrief
CVE-2026-80193 kimai CVE debrief
Kimai before version 2.62.0 is vulnerable to an authorization bypass via the QuickEntry controller. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members, bypassing authorization checks enforced elsewhere. This vulnerability impacts Kimai installations where users have limited permissions, as they can create timesheets for team members without proper authorization. The CVE record was published on 2026-08-26T05:18:26.617Z and has not been modified since then. Evidence is limited to CVE Program and NVD records, which may not cover all affected deployments or configurations. Defenders should verify Kimai version and exposure, review QuickEntry controller permissions, and monitor for suspicious timesheet creation activity. The vulnerability has a CVSS score of 8.7 and is classified as HIGH severity. Users of Kimai versions before 2.62.0, administrators of Kimai installations, security teams monitoring for potential authorization bypass vulnerabilities, and operators responsible for managing user permissions and access controls in Kimai environments should be aware of this vulnerability.
- Vendor
- kimai
- Product
- Unknown
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-26
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-26
- Advisory updated
- 2026-08-31
Who should care
Users of Kimai versions before 2.62.0, administrators of Kimai installations, security teams monitoring for potential authorization bypass vulnerabilities, and operators responsible for managing user permissions and access controls in Kimai environments should be aware of this vulnerability. They should review and update permissions, monitor for suspicious activity, and plan for updates or mitigations as needed to prevent unauthorized timesheet creation.
Technical summary
Kimai before version 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller. This allows authenticated users with view_other_timesheet and edit_other_timesheet permissions to create timesheet records for team members, bypassing authorization checks enforced elsewhere. The vulnerability impacts Kimai installations where users have limited permissions, as they can create timesheets for team members without proper authorization.
Defensive priority
Authenticated users with limited permissions can create timesheets for team members, requiring validation of user permissions and access controls.
Recommended defensive actions
- Validate user permissions and access controls for creating timesheets
- Restrict access to QuickEntry controller for users with view_other_timesheet and edit_other_timesheet permissions
- Monitor for suspicious timesheet creation activity
- Update Kimai to version 2.62.0 or later
- Confirm whether affected Kimai deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed Kimai systems while remediation is scheduled and verified.
- Track exceptions, retest remediated Kimai assets, and close the item only after evidence is documented.
Evidence notes
The CVE record indicates that Kimai before version 2.62.0 is vulnerable to an authorization bypass via the QuickEntry controller. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members. The NVD entry is currently Deferred. Evidence is limited to CVE Program and NVD records, which may not cover all affected deployments or configurations. Defenders should verify Kimai version and exposure, review QuickEntry controller permissions, and monitor for suspicious timesheet creation activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-80193 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-80193
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-80193 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80193
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/kimai/kimai/security/advisories/GHSA-2w7f-x78f-89q2
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/kimai-before-2.62.0-authorization-bypass-via-quickentry
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.