Kimai 在 2.65.0 之前的版本中,通过 API 端点移除团队对活动、项目和客户的访问权限时,未能正确校验权限。拥有 权限的已认证用户可以绕过 检查,从而在没有相应权限的情况下撤销团队的访问权限,导致授权控制被绕过。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84807 | 5.4 MEDIUM | Kimai before 2.65.0 Authentication Bypass via Team Creation |
| CVE-2026-84806 | 5.4 MEDIUM | Kimai before 2.63.0 Authorization Bypass via Team Access Endpoints |
| CVE-2026-84808 | 4.3 MEDIUM | Kimai before 2.65.0 Authorization Bypass via API Timesheet |
| CVE-2026-84805 | 4.3 MEDIUM | Kimai 2.61.0 before 2.63.0 Authentication Bypass via API |
No comments yet