Kimai · Kimai · CVE-2026-84808
**Name of the Vulnerable Software and Affected Versions**
Kimai versions prior to 2.65.0
**Description**
An authorization bypass exists in the REST API timesheet collection endpoint. The system fails to enforce activity-team access controls, allowing users with the `view other timesheet` permission to list timesheets associated with activities restricted to teams they are not members of, which bypasses intended data isolation.
**Recommendations**
Update to version 2.65.0 or later.