Authorization Bypass Vulnerability in Kimai by Kimai Development
CVE-2026-84808
5.3MEDIUM
What is CVE-2026-84808?
Kimai versions prior to 2.65.0 are susceptible to an authorization bypass vulnerability in the REST API's timesheet collection endpoint. This flaw allows users who possess the 'view_other_timesheet' permission to access and list timesheets associated with activities that are meant to be restricted to different teams. The lack of proper access control enforcement compromises the intended data isolation, potentially exposing sensitive information to unauthorized users.
Affected Version(s)
kimai 0 < 2.65.0
kimai 2.65.0
