Kimai 在 2.63.0 之前的版本中,团队访问端点存在不恰当的授权漏洞。该漏洞允许拥有团队编辑权限和只读访问权限的已认证用户向客户、项目或活动授予团队访问权限。攻击者可以通过向团队访问端点发送 POST 请求,利用不足的权限检查机制,修改本不该由其修改的实体的访问控制列表。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84807 | 5.4 MEDIUM | Kimai before 2.65.0 Authentication Bypass via Team Creation |
| CVE-2026-84804 | 5.4 MEDIUM | Kimai before 2.65.0 Authorization Bypass via Team Activity API |
| CVE-2026-84808 | 4.3 MEDIUM | Kimai before 2.65.0 Authorization Bypass via API Timesheet |
| CVE-2026-84805 | 4.3 MEDIUM | Kimai 2.61.0 before 2.63.0 Authentication Bypass via API |
No comments yet