SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84808

MEDIUM · CVSS 4.3 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Versions of Kimai prior to 2.65.0 are vulnerable to an authorization bypass in the REST API timesheet collection endpoint, allowing users with the view_other_timesheet permission to access timesheets associated with activities outside their designated teams. This flaw compromises data isolation and could lead to unauthorized exposure of sensitive timesheet information. Organizations utilizing Kimai should prioritize patching to mitigate potential data breaches and ensure compliance with access control policies.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84808
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%

Original NVD Description

Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls. Users with view_other_timesheet permission can list timesheets using activities restricted to teams they do not belong to, bypassing intended data isolation.