Authorization Bypass in Kimai Affects Team Access Controls
CVE-2026-84804

5.3MEDIUM

Key Information:

Vendor

Kimai

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-84804?

The vulnerability in Kimai prior to version 2.65.0 allows authenticated users possessing the edit_team permission to improperly remove team access to activities, projects, and customers. This is facilitated through the API endpoints without performing the required permissions_activity checks, leading to a lapse in the established authorization controls. Users could exploit this flaw to bypass security measures and manipulate team access, potentially compromising the integrity of project management and client information.

Affected Version(s)

kimai 0 < 2.65.0

kimai 2.65.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ashrexon
.