CVE-2026-84808
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Sep 02, 2026
Vendor
unknown
Description
Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls. Users with view_other_timesheet permission can list timesheets using activities restricted to teams they do not belong to, bypassing intended data isolation.