Kimai(kimai/kimai)版本 2.65.0 及之前版本中存在一个业务逻辑/不当授权漏洞,位于默认的团队创建端点。拥有项目权限管理权限的已认证用户,可以创建或引用一个名称与现有团队相同的客户、项目或活动。由于端点 、 和 会复用同名现有团队,并在未验证当前用户是否有权管理该团队的情况下,将当前用户添加为团队负责人,攻击者因此可获取该现有团队的管理员(团队负责人)权限。该漏洞已在 2.65.0 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84806 | 5.4 MEDIUM | Kimai before 2.63.0 Authorization Bypass via Team Access Endpoints |
| CVE-2026-84804 | 5.4 MEDIUM | Kimai before 2.65.0 Authorization Bypass via Team Activity API |
| CVE-2026-84808 | 4.3 MEDIUM | Kimai before 2.65.0 Authorization Bypass via API Timesheet |
| CVE-2026-84805 | 4.3 MEDIUM | Kimai 2.61.0 before 2.63.0 Authentication Bypass via API |
No comments yet