Authorization Bypass in Kimai Affects Team Access Controls
CVE-2026-84804
5.3MEDIUM
What is CVE-2026-84804?
The vulnerability in Kimai prior to version 2.65.0 allows authenticated users possessing the edit_team permission to improperly remove team access to activities, projects, and customers. This is facilitated through the API endpoints without performing the required permissions_activity checks, leading to a lapse in the established authorization controls. Users could exploit this flaw to bypass security measures and manipulate team access, potentially compromising the integrity of project management and client information.
Affected Version(s)
kimai 0 < 2.65.0
kimai 2.65.0
