CVE-2026-80197
Received Received - Intake

Improper Authorization in Kimai Timesheet Management

Vulnerability report for CVE-2026-80197, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: VulnCheck

Description

Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that allows authenticated users to manipulate other users' bookmarks. Attackers can add or remove timesheet entries from another user's favorite list by referencing their timesheet identifier, enabling cross-user business-state tampering without administrative privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-26
AI Q&A
2026-08-26
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kimai kimai to 2.57.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper authorization flaw in Kimai versions before 2.57.0. It allows authenticated users to manipulate other users' favorite timesheet bookmarks by referencing a timesheet ID belonging to the victim. The endpoints do not verify ownership, enabling attackers to add or remove entries without admin privileges.

Detection Guidance

To detect this vulnerability, check if your Kimai instance is running a version prior to 2.57.0. Use commands like 'curl -s https://your-kimai-instance.com/api/version' or check the version in the admin panel. If the version is below 2.57.0, the system is vulnerable.

Impact Analysis

An attacker could disrupt a victim's timesheet workflow by adding or removing entries from their favorite list. This could cause confusion, misreporting of hours, or workflow disruptions. No sensitive data is directly exposed, but business operations may be affected.

Mitigation Strategies

Immediately upgrade Kimai to version 2.57.0 or later. This patched version resolves the improper authorization flaw in the favorite timesheet endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80197. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart