Junglewise Threat Intelligence

CVE-2026-84807: Kimai improper authorization in team creation endpoints

CVE-2026-84807 · Severity: medium · CVSS 5.4 · Published 2026-09-02

Technologies: Kimai. Vendors: Kimai.

Executive brief

Kimai is a time-tracking and project management application. An authenticated user with project management privileges can gain unauthorized administrative access to existing teams by creating resources (customers, projects, or activities) with names matching existing teams. This allows attackers to hijack team administration rights without proper authorization, potentially compromising access controls and team data.

Technical details

This is a business logic and improper authorization vulnerability (CWE-266, CWE-863) in Kimai's team creation API endpoints. The vulnerable endpoints (POST /api/customers/{id}/team, POST /api/projects/{id}/team, POST /api/activities/{id}/team) reuse existing teams matching the name of the resource being created and automatically add the requesting user as teamlead, without verifying the user has authorization to manage that team. Attack requires network access and authentication with project permission-management privileges. An attacker can exploit this to gain unauthorized team-lead (administrative) rights over existing teams. The vulnerability was patched in version 2.65.0 by removing team reuse logic and moving team creation to the web interface where teams are always created fresh.

Affected products

  • Kimai Kimai through 2.65.0

Timeline

  • 2026-08-19: disclosed
  • 2026-09-02: advisory
  • 2026-09-02: patched: fixed in version 2.65.0

References

Related threats