Sploitus

CVE-2026-28685

No indexed exploits for CVE-2026-28685 yet

Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks the role-based view_invoice permission but does not verify the requesting user has access to the invoice's customer. Any user with ROLE_TEAMLEAD (which grants view_invoice) can read all invoices in the system, including those belonging to customers assigned to other teams. This issue has been patched in version 2.51.0.

Affected products
Kimai
Kimai
< 2.51.0
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
0.4% (33th percentile)
Weakness
CWE-285
NVD status
Analyzed
Published
2026-03-06
CVE-2026-28685 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-28685 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-28685 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.