CVE-2026-84808 Kimai versions before 2.65.0 contain an authorization… — CVE Notify — TG.ME

🚨 CVE-2026-84808
Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls. Users with view_other_timesheet permission can list timesheets using activities restricted to teams they do not belong to, bypassing intended data isolation.

🎖@cveNotify
GitHub
API Timesheet lists ignore team restrictions on activities
## Summary The Kimai REST API timesheet collection endpoint (`GET /api/timesheets`) returns records that bypass activity-team access controls. A teamlead or any user with `view_other_timesheet` ...
September 2, 2026 48