Business Logic Flaw in Kimai Team Management API
CVE-2026-80195
8.7HIGH
What is CVE-2026-80195?
Before version 2.63.0, Kimai suffered from a business logic vulnerability in the team update API. This flaw allowed an authenticated user with team editing permissions to submit a malformed payload to remove existing team members without proper validation. Even though the system returned a validation error, the existing members were already deleted prior to this check, potentially leaving a team with no members or leaders. Such an issue circumvents established protections against unintended removals, severely disrupting team-based access controls.
Affected Version(s)
kimai 0 < 2.63.0
kimai 2.63.0
