SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84806

MEDIUM · CVSS 5.4 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Kimai versions prior to 2.63.0 are vulnerable due to improper authorization in team access endpoints, allowing authenticated users with team edit permissions to improperly grant access to customers, projects, or activities. This vulnerability can be exploited by attackers to manipulate access control lists through crafted POST requests, potentially leading to unauthorized access to sensitive data. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized data exposure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84806
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%

Original NVD Description

Kimai before 2.63.0 contains an improper authorization vulnerability in team access endpoints that allows authenticated users with team edit permissions and read-only access to grant team access to customers, projects, or activities. Attackers can exploit insufficient permission checks by sending POST requests to team access endpoints to modify access control lists for entities they should not be able to modify.