Missing Authorization in Kimai's ProjectViewController Export Functionality
CVE-2026-80194
8.7HIGH
What is CVE-2026-80194?
A missing authorization vulnerability exists in the ProjectViewController export route of Kimai prior to version 2.64.0. The issue arises because authorization guards are applied to the sibling invoke method rather than at the class level, resulting in a lack of necessary checks for the export route. Consequently, any authenticated user can access project overview exports, unwittingly disclosing sensitive information, including customer names, project identifiers, currency types, budget classifications, and aggregate financial data across all clients. However, specific financial figures remain protected within the export template.
Affected Version(s)
kimai 0 < 2.64.0
kimai 2.64.0
