[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-80202":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-26T04:49:15.964Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":20,"aliases":21,"duplicate_of":9,"upstream":22,"downstream":23,"duplicates":24,"related":25,"reserved_at":9,"published_at":26,"modified_at":26,"state":27,"summary":28,"references_raw":35,"kevs":46,"epss":9,"epss_history":47,"metrics":48,"affected":58},"CVE-2026-80202","Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timesheet. As a result, any authenticated user with ROLE_TEAMLEAD (or a role holding edit_other_timesheet/delete_other_timesheet) can read, modify, and permanently delete timesheets belonging to any user system-wide via the API, regardless of team membership. Timesheet IDs are sequential integers and trivially enumerable. ROLE_USER accounts are correctly restricted. (Note: the maintainers characterize this behavior as matching the documented permission model.)",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-863","Incorrect Authorization","The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.","weakness","Incomplete","Class","High",[],[],[],[],[],[],[],"2026-08-25T23:19:07.165Z","PUBLISHED",{"cisa_kev":29,"cisa_ransomware":29,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":30,"severity_score":31,"severity_version":32,"severity_source":33,"severity_vector":34,"severity_status":27},false,"critical",9.3,"v4.0","cve.org","CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",[36,41],{"url":37,"sources":38,"tags":39},"https://github.com/kimai/kimai/security/advisories/GHSA-9g2q-w3w2-vf7q",[33],[40],"Vendor Advisory",{"url":42,"sources":43,"tags":44},"https://www.vulncheck.com/advisories/kimai-before-2.56.0-authorization-bypass-via-timesheetvoter",[33],[45],"Third Party Advisory",[],[],[49],{"source":33,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":50,"cvss_v4_0":56},{"baseScore":51,"baseSeverity":52,"vectorString":53,"impactScore":54,"exploitabilityScore":55},8.8,"HIGH","CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",9.8,7.2,{"baseScore":31,"baseSeverity":57,"vectorString":34,"impactScore":9,"exploitabilityScore":9},"CRITICAL",[59],{"ecosystem":9,"name":60,"vendor":60,"product":60,"cpe_part":61,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":62},"kimai","a",[63],{"version":64,"is_range":65,"range_type":33,"version_start":9,"version_start_type":9,"version_end":66,"version_end_type":67,"fixed_in":9},"\u003C 2.56.0",true,"2.56.0","excluding"]