Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 26 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timesheet. As a result, any authenticated user with ROLE_TEAMLEAD (or a role holding edit_other_timesheet/delete_other_timesheet) can read, modify, and permanently delete timesheets belonging to any user system-wide via the API, regardless of team membership. Timesheet IDs are sequential integers and trivially enumerable. ROLE_USER accounts are correctly restricted. (Note: the maintainers characterize this behavior as matching the documented permission model.) | |
| Title | Kimai before 2.56.0 Authorization Bypass via TimesheetVoter | |
| First Time appeared |
Kimai
Kimai kimai |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:kimai:kimai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kimai
Kimai kimai |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-26T13:55:11.219Z
Reserved: 2026-08-25T23:15:39.155Z
Link: CVE-2026-80202
Updated: 2026-08-26T13:54:45.492Z
Status : Received
Published: 2026-08-26T05:18:27.980
Modified: 2026-08-26T14:17:17.107
Link: CVE-2026-80202
No data.
OpenCVE Enrichment
Updated: 2026-08-26T01:15:04Z
-
CWE-863
Incorrect Authorization