PT-2026-84677 · Kimai · Kimai

·

CVE-2026-84804

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Kimai versions prior to 2.65.0
Description Authenticated users with edit team permission can bypass authorization controls when removing team access to activities, projects, and customers via API endpoints. The system fails to perform the necessary permissions activity check, allowing users to revoke access without the required authorization.
Recommendations Update to version 2.65.0 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84804
GHSA-MC86-77VP-82G3

Affected Products

Kimai