Junglewise Threat Intelligence

CVE-2026-80193: Kimai QuickEntry authorization bypass in timesheet creation

CVE-2026-80193 · Severity: high · CVSS 8.8 · Published 2026-08-26

Technologies: Kimai. Vendors: Kimai.

Executive brief

Kimai is a time-tracking application used to record and manage employee work hours for billing and payroll purposes. A flaw in the QuickEntry timesheet form allows authenticated users to create new timesheet records for team members even when they lack the explicit permission to do so. Attackers could fabricate billable hours, inflate project budgets, or falsely attribute work to other employees, directly impacting billing accuracy and payroll integrity.

Technical details

The QuickEntry controller in Kimai before version 2.62.0 fails to validate the create_other_timesheet permission when processing new timesheet submissions. The vulnerability exists in src/Controller/QuickEntryController.php where the user-switcher is gated by view_other_timesheet instead of create_other_timesheet (line 59), and new timesheet records (id === null) are unconditionally forwarded to updateMultipleTimesheets() without authorization checks (lines 274-285). An authenticated attacker with view_other_timesheet and edit_other_timesheet permissions but explicitly denied create_other_timesheet can exploit this by submitting the QuickEntry form with a duration for a new timesheet row, creating fraudulent time records for team members they oversee. The fix, already released in version 2.62.0, adds proper authorization validation to gate the user-switcher by the correct permission and validates creation rights before processing new records.

Affected products

  • Kimai Kimai before 2.62.0

Timeline

  • 2026-08-09: disclosed: GHSA-2w7f-x78f-89q2 published by GitHub
  • 2026-07-09: patched: Fix released in version 2.62.0 (three weeks before advisory submission)
  • 2026-08-26: other: CVE-2026-80193 published

References

Related threats