Sploitus

CVE-2026-84805

No indexed exploits for CVE-2026-84805 yet

Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract preferences for low-privilege users in the PATCH /api/users/{id}/preferences endpoint. Although the web interface gates these employment-contract fields behind the contract_other_profile admin permission, the WorkContractPreferenceSubscriber (introduced in 2.61.0) registers the preferences as enabled without a permission check, so an authenticated regular user can use the API to modify their own admin-only work-contract data. The issue is fixed in 2.63.0 by applying the same permission check to the API endpoint.

Affected products
Kimai
Fix
Available
CVSS 4.0
5.3 MEDIUM
CVSS 3.1
4.3 MEDIUM
EPSS
0.2% (12th percentile)
Weakness
CWE-862
NVD status
Deferred
Published
2026-09-02
CVE-2026-84805 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-84805 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-84805 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.