Medium severity4.3NVD Advisory· Published Sep 2, 2026· Updated Sep 2, 2026
CVE-2026-84808
CVE-2026-84808
Description
Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls. Users with view_other_timesheet permission can list timesheets using activities restricted to teams they do not belong to, bypassing intended data isolation.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.