CVE-2026-80202: Kimai before 2.56.0 Authorization Bypass via TimesheetVoter

Published Aug 25, 2026
·
Updated

Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to owntimesheet or othertimesheet. As a result, any authenticated user with ROLETEAMLEAD (or a role holding editothertimesheet/deleteothertimesheet) can read, modify, and permanently delete timesheets belonging to any user system-wide via the API, regardless of team membership. Timesheet IDs are sequential integers and trivially enumerable. ROLEUSER accounts are correctly restricted. (Note: the maintainers characterize this behavior as matching the documented permission model.)

Affected Software

1 affected component
Kimai Kimai<2.56.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Kimai to a version that resolves this vulnerability.

    Fixed in 2.56.0Patch Kimai before 2.56.0 Authorization Bypass via TimesheetVoter

Event History

Aug 25, 2026
CVE Published
via MITRE·11:19 PM
Data Sourced
via MITRE·11:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which accounts can access timesheets outside their teams?

Authenticated users with ROLE_TEAMLEAD, or any role granted edit_other_timesheet or delete_other_timesheet, can read, modify, or permanently delete timesheets belonging to any user. Accounts limited to ROLE_USER are correctly restricted.

2

What does an attacker need to exploit this issue?

The attacker needs a valid authenticated account with the affected role or permissions and access to the API. Timesheet IDs are sequential integers, making target records trivially enumerable.

3

Are installations using the default ROLE_USER permissions affected?

ROLE_USER accounts are correctly restricted. Exposure depends on whether users have ROLE_TEAMLEAD or roles that include edit_other_timesheet or delete_other_timesheet.

4

How can I identify potentially affected activity?

Review API activity by ROLE_TEAMLEAD users and roles holding edit_other_timesheet or delete_other_timesheet for access, changes, or deletions involving timesheets owned by users outside the actor's team. The affected behavior permits read, modify, and permanent deletion operations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203