PT-2026-84678 · Kimai · Kimai

·

CVE-2026-84805

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kimai versions 2.61.0 through 2.62.x
Description Low-privilege users can modify their own admin-only work-contract data because the system fails to enforce permission checks for certain preferences. While the web interface restricts these fields using the contract other profile admin permission, the WorkContractPreferenceSubscriber registers these preferences as enabled without verification. This allows an authenticated regular user to bypass restrictions via the PATCH '/api/users/{id}/preferences' endpoint.
Recommendations Update Kimai to version 2.63.0. Restrict access to the PATCH '/api/users/{id}/preferences' endpoint for low-privilege users to prevent unauthorized modification of work-contract data.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84805
GHSA-5MPC-5CG2-G99R

Affected Products

Kimai