SB2026081394 - Missing Authorization in kimai2



SB2026081394 - Missing Authorization in kimai2

Published: August 13, 2026

Security Bulletin ID SB2026081394
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in ProjectViewController::export when handling requests to the report_project_view_export route. A remote user can send a request to the export endpoint to disclose sensitive information.

The exposed data can include customer names, project names, currency, budget type, and aggregate totals, while financial figures remain protected.


Remediation

Install update from vendor's website.