CVE-2026-80195
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which removes all existing team members before validating the submitted replacement member list. An authenticated teamlead (or other user) with permission to edit a team can submit a malformed members payload; although Kimai returns a validation error, the existing membership rows have already been deleted. This bypasses the dedicated member-removal endpoint's protection against removing teamleaders and can leave a team with no members or teamleaders, disrupting team-based access control.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| kimai | kimai | 0 < 2.63.0 | affected |
| kimai | kimai | 2.63.0 | unaffected |
Weaknesses
- CWE-841: Improper Enforcement of Behavioral Workflow
References
- https://github.com/kimai/kimai/security/advisories/GHSA-6rxf-4hh9-pp46
- https://www.vulncheck.com/advisories/kimai-before-2.63.0-team-membership-removal-via-api
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.