Improper Enforcement of Behavioral Workflow in kimai2 - CVE-2026-80195
Published: August 13, 2026 / Updated: September 14, 2026
Vulnerability details
The vulnerability allows a remote user to remove all members and teamleaders from a team.
The vulnerability exists due to improper enforcement of behavioral workflow in the team update API endpoint when processing a malformed members payload. A remote user can submit a malformed members value to remove all members and teamleaders from a team.
This bypasses the intended protection in the dedicated member-removal endpoint that prevents direct removal of teamleaders.