CVE-2026-80193

Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members by submitting the QuickEntry form, bypassing authorization checks enforced elsewhere.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-26 05:18

Updated : 2026-08-31 20:52


NVD link : CVE-2026-80193

Mitre link : CVE-2026-80193

CVE.ORG link : CVE-2026-80193


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization