CVE-2026-80195
Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which removes all existing team members before validating the submitted replacement member list. An authenticated teamlead (or other user) with permission to edit a team can submit a malformed members payload; although Kimai returns a validation error, the existing membership rows have already been deleted. This bypasses the dedicated member-removal endpoint's protection against removing teamleaders and can leave a team with no members or teamleaders, disrupting team-based access control.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.28%
- CWE
- CWE-841
- Published
- 2026-08-25
- Last modified
- 2026-08-26
Affected products
- kimai kimai
- kimai kimai
Weakness type
Related vulnerabilities
- CVE-2026-87503 — Inappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36...
- CVE-2026-53637 — Sylius: Cart FormComponent allows modification or deletion of an already-completed order
- CVE-2026-67279 — SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS
- CVE-2026-82423 — macrozheng mall Payment Status Endpoint paySuccess behavioral workflow
- CVE-2026-55763 — Klever-Go: Percentage-transfer royalty skips the source debit at exactly-100% splits
- CVE-2026-78103 — Dimension Log Server Configuration Lock Bypass Vulnerability
- CVE-2026-78618 — Dimension Business Logic Flaw Allows Chained Backend Object Operations
- CVE-2026-77508 — Weblate: Unverified REST API email changes