Missing Authorization in Kimai's ProjectViewController Export Functionality
CVE-2026-80194

8.7HIGH

Key Information:

Vendor

Kimai

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-80194?

A missing authorization vulnerability exists in the ProjectViewController export route of Kimai prior to version 2.64.0. The issue arises because authorization guards are applied to the sibling invoke method rather than at the class level, resulting in a lack of necessary checks for the export route. Consequently, any authenticated user can access project overview exports, unwittingly disclosing sensitive information, including customer names, project identifiers, currency types, budget classifications, and aggregate financial data across all clients. However, specific financial figures remain protected within the export template.

Affected Version(s)

kimai 0 < 2.64.0

kimai 2.64.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

devzephyr
.