Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls. Users with viewothertimesheet permission can list timesheets using activities restricted to teams they do not belong to, bypassing intended data isolation.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84808.json",
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-863"
]
}