PatchSiren

kimai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH kimai CVE published 2026-08-26

CVE-2026-80193

Kimai before version 2.62.0 is vulnerable to an authorization bypass via the QuickEntry controller. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members, bypassing authorization checks enforced elsewhere. This vulnerability impacts Kimai installations where users have limited permissions, as they can create timesheets for team mem [truncated]