PT-2026-81908 · Kimai · Kimai

·

CVE-2026-80195

·

Published

2026-08-25

·

Updated

2026-09-03

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kimai versions prior to 2.63.0
Description An improper authorization and business logic issue exists in the 'PATCH /api/teams/{id}' API endpoint. The system removes all current team members before validating the new member list provided in the request. An authenticated user with team editing permissions can send a malformed members payload, causing the system to delete existing membership records even if a validation error is returned. This process bypasses protections that normally prevent the removal of teamleaders, potentially leaving a team without any members or leadership and disrupting access control.
Recommendations Update to version 2.63.0 or later. Avoid using the members parameter in the 'PATCH /api/teams/{id}' endpoint until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80195
GHSA-6RXF-4HH9-PP46

Affected Products

Kimai