HIGH
kimai
CVE published 2026-08-26
CVE-2026-80193
Kimai before version 2.62.0 is vulnerable to an authorization bypass via the QuickEntry controller. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members, bypassing authorization checks enforced elsewhere. This vulnerability impacts Kimai installations where users have limited permissions, as they can create timesheets for team mem [truncated]