Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80195— Kimai before 2.63.0 Team Membership Removal via API

Quick assessment

Affected
kimai kimai
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Kimai 版本低于 2.63.0 的版本中,团队更新 API 端点(PATCH /api/teams/{id})存在业务逻辑缺陷和授权不当漏洞。该漏洞会在验证提交的替换成员列表之前,先删除所有现有的团队成员记录。一个经过身份验证且具有编辑团队权限的用户(例如团队负责人或其他用户)可以提交一个格式不正确的成员载荷(payload)。尽管 Kimai 会返回验证错误,但现有的成员记录已经被删除。这一行为绕过了专门用于成员移除的端点中对“移除团队负责人”的保护机制,可能导致某个团队没有任何成员或团队负责人,从而破坏

CVSS 5.4 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80195

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kimai before 2.63.0 Team Membership Removal via API
Source: CVE Program / CVE List V5
Vulnerability Description
Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which removes all existing team members before validating the submitted replacement member list. An authenticated teamlead (or other user) with permission to edit a team can submit a malformed members payload; although Kimai returns a validation error, the existing membership rows have already been deleted. This bypasses the dedicated member-removal endpoint's protection against removing teamleaders and can leave a team with no members or teamleaders, disrupting team-based access control.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
行为工作流的不恰当实施
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
kimai kimai 0 ~ 2.63.0 -

II. Public POCs for CVE-2026-80195

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80195

登录查看更多情报信息。

Vendor Advisories for CVE-2026-80195 (2)

Same Patch Batch · kimai · 2026-08-25 · 10 CVEs total

CVE-2026-80193 8.8 HIGH Kimai before 2.62.0 Authorization Bypass via QuickEntry
CVE-2026-80202 8.8 HIGH Kimai before 2.56.0 Authorization Bypass via TimesheetVoter
CVE-2026-80196 7.5 HIGH Kimai before 2.58.0 Authentication Bypass via Password Reset Link
CVE-2026-80198 7.5 HIGH Kimai before 2.56.0 Information Disclosure via config() Twig Function
CVE-2026-80194 4.3 MEDIUM Kimai before 2.64.0 Missing Authorization via ProjectViewController export
CVE-2026-80197 4.3 MEDIUM Kimai before 2.57.0 Improper Authorization via Favorite Endpoints
CVE-2026-80199 3.7 LOW Kimai before 2.54.0 Username Enumeration via Timing Oracle
CVE-2026-80201 2.0 LOW Kimai before 2.53.0 API Token Leakage via Invoice Template
CVE-2026-80200 Kimai before 2.53.0 Open Redirect via RelayState

IV. Related Vulnerabilities

V. Comments for CVE-2026-80195

No comments yet


Leave a comment