Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-84808

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Sep 02, 2026
Vendor unknown

Description

Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls. Users with view_other_timesheet permission can list timesheets using activities restricted to teams they do not belong to, bypassing intended data isolation.

References