Sploitus

CVE-2026-80194

No indexed exploits for CVE-2026-80194 yet

Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_project_view_export). The authorization guards are attached to the sibling __invoke method rather than at the class level, so the export route inherits no authorization checks. Any authenticated user, including a plain ROLE_USER without the project_reporting permission, can download the project overview export - which returns the same dataset as the protected report - disclosing customer names, project names, currency, budget type, and aggregate totals across all customers. Actual financial figures remain protected in the export template.

Affected products
Kimai
CVSS 4.0
8.7 HIGH
CVSS 3.1
4.3 MEDIUM
EPSS
0.2% (15th percentile)
Weakness
CWE-200
NVD status
Deferred
Published
2026-08-25
CVE-2026-80194 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-80194 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-80194 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.