PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-80193 kimai CVE debrief

Kimai before version 2.62.0 is vulnerable to an authorization bypass via the QuickEntry controller. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members, bypassing authorization checks enforced elsewhere. This vulnerability impacts Kimai installations where users have limited permissions, as they can create timesheets for team members without proper authorization. The CVE record was published on 2026-08-26T05:18:26.617Z and has not been modified since then. Evidence is limited to CVE Program and NVD records, which may not cover all affected deployments or configurations. Defenders should verify Kimai version and exposure, review QuickEntry controller permissions, and monitor for suspicious timesheet creation activity. The vulnerability has a CVSS score of 8.7 and is classified as HIGH severity. Users of Kimai versions before 2.62.0, administrators of Kimai installations, security teams monitoring for potential authorization bypass vulnerabilities, and operators responsible for managing user permissions and access controls in Kimai environments should be aware of this vulnerability.

Vendor
kimai
Product
Unknown
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-26
Original CVE updated
2026-08-31
Advisory published
2026-08-26
Advisory updated
2026-08-31

Who should care

Users of Kimai versions before 2.62.0, administrators of Kimai installations, security teams monitoring for potential authorization bypass vulnerabilities, and operators responsible for managing user permissions and access controls in Kimai environments should be aware of this vulnerability. They should review and update permissions, monitor for suspicious activity, and plan for updates or mitigations as needed to prevent unauthorized timesheet creation.

Technical summary

Kimai before version 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller. This allows authenticated users with view_other_timesheet and edit_other_timesheet permissions to create timesheet records for team members, bypassing authorization checks enforced elsewhere. The vulnerability impacts Kimai installations where users have limited permissions, as they can create timesheets for team members without proper authorization.

Defensive priority

Authenticated users with limited permissions can create timesheets for team members, requiring validation of user permissions and access controls.

Recommended defensive actions

  • Validate user permissions and access controls for creating timesheets
  • Restrict access to QuickEntry controller for users with view_other_timesheet and edit_other_timesheet permissions
  • Monitor for suspicious timesheet creation activity
  • Update Kimai to version 2.62.0 or later
  • Confirm whether affected Kimai deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed Kimai systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated Kimai assets, and close the item only after evidence is documented.

Evidence notes

The CVE record indicates that Kimai before version 2.62.0 is vulnerable to an authorization bypass via the QuickEntry controller. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members. The NVD entry is currently Deferred. Evidence is limited to CVE Program and NVD records, which may not cover all affected deployments or configurations. Defenders should verify Kimai version and exposure, review QuickEntry controller permissions, and monitor for suspicious timesheet creation activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-80193 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-80193

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-80193 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80193

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.