Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80194— Kimai before 2.64.0 Missing Authorization via ProjectViewController export

Quick assessment

Affected
kimai kimai
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kimai 版本低于 2.64.0 存在一个缺失授权检查的漏洞,位于 的导出路由( )。该路由的授权守卫被绑定在其兄弟方法 上,而非设置在类级别,因此导出路由未继承任何授权检查。任何经过认证的用户(即使只是普通 角色,且不具备 权限)均可下载项目概览导出文件,该导出文件返回与受保护的报告相同的数据集,包括所有客户的客户名称、项目名称、货币类型、预算类型以及汇总金额。实际财务金额在导出模板中仍受到保护。

CVSS 4.3 · Medium

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80194

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kimai before 2.64.0 Missing Authorization via ProjectViewController export
Source: CVE Program / CVE List V5
Vulnerability Description
Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_project_view_export). The authorization guards are attached to the sibling __invoke method rather than at the class level, so the export route inherits no authorization checks. Any authenticated user, including a plain ROLE_USER without the project_reporting permission, can download the project overview export - which returns the same dataset as the protected report - disclosing customer names, project names, currency, budget type, and aggregate totals across all customers. Actual financial figures remain protected in the export template.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
kimai kimai 0 ~ 2.64.0 -

II. Public POCs for CVE-2026-80194

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80194

登录查看更多情报信息。

Vendor Advisories for CVE-2026-80194 (2)

Same Patch Batch · kimai · 2026-08-25 · 10 CVEs total

CVE-2026-80193 8.8 HIGH Kimai before 2.62.0 Authorization Bypass via QuickEntry
CVE-2026-80202 8.8 HIGH Kimai before 2.56.0 Authorization Bypass via TimesheetVoter
CVE-2026-80196 7.5 HIGH Kimai before 2.58.0 Authentication Bypass via Password Reset Link
CVE-2026-80198 7.5 HIGH Kimai before 2.56.0 Information Disclosure via config() Twig Function
CVE-2026-80195 5.4 MEDIUM Kimai before 2.63.0 Team Membership Removal via API
CVE-2026-80197 4.3 MEDIUM Kimai before 2.57.0 Improper Authorization via Favorite Endpoints
CVE-2026-80199 3.7 LOW Kimai before 2.54.0 Username Enumeration via Timing Oracle
CVE-2026-80201 2.0 LOW Kimai before 2.53.0 API Token Leakage via Invoice Template
CVE-2026-80200 Kimai before 2.53.0 Open Redirect via RelayState

IV. Related Vulnerabilities

V. Comments for CVE-2026-80194

No comments yet


Leave a comment