Junglewise Threat Intelligence

CVE-2026-80197: Kimai improper authorization in favorite timesheet endpoints

CVE-2026-80197 · Severity: medium · CVSS 4.3 · Published 2026-08-26

Technologies: kimai/kimai (Packagist), Kimai. Vendors: Packagist, Kimai.

Executive brief

Kimai is a time-tracking and project management application used by teams to log and manage work hours. A vulnerability in the favorite timesheet feature allows any authenticated user to manipulate another user's bookmarked timesheets—adding or removing entries from their favorites list—without permission, disrupting their workflow and normal operations without requiring administrative access.

Technical details

The vulnerability is an improper authorization (IDOR) flaw in the GET /en/favorite/timesheet/add/{id} and GET /en/favorite/timesheet/remove/{id} endpoints. The affected controller (FavoriteController.php) accepts a user-controlled timesheet identifier but fails to verify that the timesheet belongs to the authenticated user; instead, it derives the bookmark owner from the timesheet object itself rather than the current session user. An attacker with the generic start_own_timesheet permission can reference another user's timesheet ID to add or remove it from that user's favorites. The vulnerability has been patched in Kimai 2.57.0 and affects all versions up to and including 2.56.0.

Affected products

  • Kimai Kimai before 2.57.0

Timeline

  • 2026-05-29: disclosed: GitHub Security Advisory GHSA-j5mc-p8qg-39j7 published
  • 2026-08-26: advisory: CVE-2026-80197 published
  • 2026-05-29: patched: Fixed in Kimai 2.57.0

References

Related threats