Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Rajib-Mahmud

#20235of 56,330
14.1Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-85513
8.8
2026-09-04
Snipe-It · Snipe-It · CVE-2026-85617
**Name of the Vulnerable Software and Affected Versions** snipe-it versions prior to 8.6.3 **Description** An authorization bypass exists in the bulk delete functionality. This issue allows restricted users to perform a soft-delete on users outside their authorized scope by including unauthorized user IDs in bulk delete requests, enabling them to modify or disable accounts they are not permitted to access. **Recommendations** Update snipe-it to version 8.6.3 or later.
PT-2026-84681
5.3
2026-09-02
Kimai · Kimai · CVE-2026-84808
**Name of the Vulnerable Software and Affected Versions** Kimai versions prior to 2.65.0 **Description** An authorization bypass exists in the REST API timesheet collection endpoint. The system fails to enforce activity-team access controls, allowing users with the `view other timesheet` permission to list timesheets associated with activities restricted to teams they are not members of, which bypasses intended data isolation. **Recommendations** Update to version 2.65.0 or later.