PT-2026-81907 · Kimai · Kimai

·

CVE-2026-80194

·

Published

2026-08-25

·

Updated

2026-08-26

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kimai versions prior to 2.64.0
Description An authorization failure exists in the report project view export export route within the ProjectViewController. Because authorization guards are applied to the invoke() function instead of the class level, the export route lacks necessary authorization checks. This allows any authenticated user, including those with only ROLE USER and lacking the project reporting permission, to download the project overview export. This action discloses customer names, project names, currency, budget type, and aggregate totals across all customers, although actual financial figures remain protected.
Recommendations Update Kimai to version 2.64.0 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80194
GHSA-PVC4-CRG3-GJ44

Affected Products

Kimai