Sploitus

CVE-2026-84808

No indexed exploits for CVE-2026-84808 yet

Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls. Users with view_other_timesheet permission can list timesheets using activities restricted to teams they do not belong to, bypassing intended data isolation.

Affected products
Kimai
Fix
Available
CVSS 4.0
5.3 MEDIUM
CVSS 3.1
4.3 MEDIUM
EPSS
0.2% (8th percentile)
Weakness
CWE-863
NVD status
Deferred
Published
2026-09-02
CVE-2026-84808 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-84808 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-84808 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.