Authorization Flaw in Kimai Multi-user Time Tracking Application
CVE-2026-28685
6.5MEDIUM
What is CVE-2026-28685?
Kimai, a web-based multi-user time-tracking application, has an authorization flaw that allows users with ROLE_TEAMLEAD to access all invoices in the system, irrespective of the associated customers. This issue arises because the application does not properly verify if the requesting user has the appropriate permissions for the specific customer tied to the invoice. This vulnerability impacts all versions prior to 2.51.0 and has been addressed in the latest update.
Affected Version(s)
kimai < 2.51.0
