← Back to overview

Kimai versions before 2.62.0 contain an authorization bypass vulnerability in the QuickEntry controller. The flaw allows authenticated users who possess view_other_timesheet and edit_other_timesheet permissions to create timesheet records for other team members without having the required create_other_timesheet permission. This occurs because the QuickEntry controller fails to validate the create_other_timesheet permission during timesheet creation. The vulnerability bypasses authorization checks that are properly enforced in other parts of the application. It affects all Kimai installations running versions prior to 2.62.0. The fix is available in Kimai 2.62.0, which properly enforces permission validation in the QuickEntry controller. Organizations using Kimai for time tracking should upgrade immediately to mitigate unauthorized timesheet manipulation risks.

Affected products

  • Kimai before 2.62.0

Related CVE's

  • CVE-2026-80193

Categories

  • Enterprise Applications
  • Identity & Access
  • Web Technologies