SB2026081394 - Missing Authorization in kimai2
Published: August 13, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in ProjectViewController::export when handling requests to the report_project_view_export route. A remote user can send a request to the export endpoint to disclose sensitive information.
The exposed data can include customer names, project names, currency, budget type, and aggregate totals, while financial figures remain protected.
Remediation
Install update from vendor's website.