PT-2026-84681 · Kimai · Kimai

·

CVE-2026-84808

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kimai versions prior to 2.65.0
Description An authorization bypass exists in the REST API timesheet collection endpoint. The system fails to enforce activity-team access controls, allowing users with the view other timesheet permission to list timesheets associated with activities restricted to teams they are not members of, which bypasses intended data isolation.
Recommendations Update to version 2.65.0 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84808
GHSA-C6J4-35FC-X3HW

Affected Products

Kimai