


Perceptive Security
SOC/SIEM Consultancy

Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timeshee…
Published:
26 augustus 2026 om 00:00:00
Alert date:
26 augustus 2026 om 18:17:38
Source:
nvd.nist.gov
Enterprise Applications, Identity & Access, Web Technologies
Kimai versions before 2.56.0 contain an authorization bypass vulnerability in TimesheetVoter::voteOnAttribute() that fails to enforce team-membership checks. The function maps permissions solely to own_timesheet or other_timesheet without verifying team relationships. Any authenticated user with ROLE_TEAMLEAD or roles granting edit_other_timesheet/delete_other_timesheet can read, modify, and permanently delete any user's timesheets system-wide via the API. Timesheet IDs are sequential integers, making enumeration trivial for attackers. ROLE_USER accounts are correctly restricted and not affected. The vulnerability was fixed in Kimai 2.56.0. The maintainers have noted this behavior aligns with their documented permission model, though it presents a significant access control risk in multi-team environments.
Technical details
Mitigation steps:
Affected products:
Kimai before 2.56.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-80202
https://github.com/kimai/kimai/security/advisories/GHSA-9g2q-w3w2-vf7q
https://www.vulncheck.com/advisories/kimai-before-2.56.0-authorization-bypass-via-timesheetvoter
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
