Missing Authorization in kimai2 - CVE-2026-41498
Published: April 21, 2026
kimai2
Detailed vulnerability description
The vulnerability allows a remote user to modify team associations and disclose limited team-related information.
The vulnerability exists due to missing authorization in Team API endpoints when handling requests to team association operations. A remote privileged user can send a specially crafted API request to modify team membership, customer assignments, project assignments, and activity assignments to modify team associations and disclose limited team-related information.
The issue is exploitable if an administrator grants the edit_team permission to a lower-privilege role through the permissions UI.