Description
Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members by submitting the QuickEntry form, bypassing authorization checks enforced elsewhere.
Published: 2026-08-25
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Kimai versions prior to 2.62.0 allow an authenticated user with the roles view_other_timesheet and edit_other_timesheet to create timesheet records for team members through the QuickEntry form. The application fails to verify whether the user has permission to create timesheets for others, so an attacker can manipulate data that should be restricted to the creator or an authorized administrator. This solely grants unauthorized data modification but does not expose system code or credentials.

Affected Systems

The vulnerability affects the Kimai time‑tracking application from the vendor kimai. Any installation of Kimai running a version earlier than 2.62.0 is affected. Earlier releases such as 2.61.x and below are vulnerable.

Risk and Exploitability

With a CVSS score of 8.7 the flaw is considered high severity. No EPSS score is published, so the current exploitation probability cannot be quantified, and the vulnerability is not yet listed in the CISA KEV catalog. It can be exploited by any authenticated user who has the view_other_timesheet and edit_other_timesheet permissions, which are typically granted to team leads or managers. The attack vector is an in‑application web form, requiring no external network access beyond normal business usage.

Generated by OpenCVE AI on August 26, 2026 at 01:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Kimai to version 2.62.0 or later to apply the vendor fix.
  • Limit or remove the view_other_timesheet and edit_other_timesheet permissions from users, granting them only to trusted administrators where necessary.
  • Disable or restrict access to the QuickEntry feature for users who do not require this capability, and monitor system logs for unauthorized timesheet creation.

Generated by OpenCVE AI on August 26, 2026 at 01:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members by submitting the QuickEntry form, bypassing authorization checks enforced elsewhere.
Title Kimai before 2.62.0 Authorization Bypass via QuickEntry
First Time appeared Kimai
Kimai kimai
Weaknesses CWE-862
CPEs cpe:2.3:a:kimai:kimai:*:*:*:*:*:*:*:*
Vendors & Products Kimai
Kimai kimai
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-25T23:19:01.048Z

Reserved: 2026-08-25T23:14:37.730Z

Link: CVE-2026-80193

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T01:45:03Z

Weaknesses