Kimai 2.65.0 之前的版本在 REST API 的工时表(timesheet)集合端点中存在一个授权绕过漏洞,该端点未能正确执行活动-团队访问控制。拥有 权限的用户可以列出仅对特定团队可见的活动对应的工时表,从而绕过了预期的数据隔离机制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84807 | 5.4 MEDIUM | Kimai before 2.65.0 Authentication Bypass via Team Creation |
| CVE-2026-84806 | 5.4 MEDIUM | Kimai before 2.63.0 Authorization Bypass via Team Access Endpoints |
| CVE-2026-84804 | 5.4 MEDIUM | Kimai before 2.65.0 Authorization Bypass via Team Activity API |
| CVE-2026-84805 | 4.3 MEDIUM | Kimai 2.61.0 before 2.63.0 Authentication Bypass via API |
No comments yet