Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that allows authenticated users to manipulate other users' bookmarks. Attackers can add or remove timesheet entries from another user's favorite list by referencing their timesheet identifier, enabling cross-user business-state tampering without administrative privileges.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Aug 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that allows authenticated users to manipulate other users' bookmarks. Attackers can add or remove timesheet entries from another user's favorite list by referencing their timesheet identifier, enabling cross-user business-state tampering without administrative privileges. | |
| Title | Kimai before 2.57.0 Improper Authorization via Favorite Endpoints | |
| First Time appeared |
Kimai
Kimai kimai |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:kimai:kimai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kimai
Kimai kimai |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T23:19:03.788Z
Reserved: 2026-08-25T23:14:37.730Z
Link: CVE-2026-80197
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-26T01:45:03Z
Weaknesses