HIGH๐Ÿ‡ต๐Ÿ‡ฑ Wersja polska

CVE-2026-80195

CVSS 8.7v4.0pub. 2026-08-26upd. 2026-09-03

Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which removes all existing team members before validating the submitted replacement member list. An authenticated teamlead (or other user) with permission to edit a team can submit a malformed members payload; although Kimai returns a validation error, the existing membership rows have already been deleted. This bypasses the dedicated member-removal endpoint's protection against removing teamleaders and can leave a team with no members or teamleaders, disrupting team-based access control.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
๐Ÿ”ต
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
CVE-2026-80195 โ€” HIGH โ€” CVSS 8.7 | CVEbaza.pl