Moderate severityNVD Advisory· Published Mar 6, 2026· Updated Mar 9, 2026
Kimai: API invoice endpoint missing customer-level access control (IDOR)
CVE-2026-28685
Description
Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks the role-based view_invoice permission but does not verify the requesting user has access to the invoice's customer. Any user with ROLE_TEAMLEAD (which grants view_invoice) can read all invoices in the system, including those belonging to customers assigned to other teams. This issue has been patched in version 2.51.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
kimai/kimaiPackagist | < 2.51.0 | 2.51.0 |
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-v33r-r6h2-8wr7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-28685ghsaADVISORY
- github.com/kimai/kimai/commit/a0601c8cb28fed1cca19051a8272425069ab758fghsax_refsource_MISCWEB
- github.com/kimai/kimai/releases/tag/2.51.0ghsax_refsource_MISCWEB
- github.com/kimai/kimai/security/advisories/GHSA-v33r-r6h2-8wr7ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.