Critical Authorization Bypass Vulnerability in Kimai Timesheet Management System
A critical vulnerability, CVE-2026-80202, with a CVSS score of 8.8, was discovered in Kimai, a popular open-source timesheet management system. The vulnerability allows any authenticated user with ROLE_TEAMLEAD or similar roles to read, modify, and permanently delete timesheets of any user system-wide via the API, bypassing team membership checks. This affects Kimai versions before 2.56.0. Immediate patching is recommended to prevent potential exploitation.