CVE-2026-80194: Kimai
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_project_view_export). The authorization guards are attached to the sibling __invoke method rather than at the class level, so the export route inherits no authorization checks. Any authenticated user, including a plain ROLE_USER without the project_reporting permission, can download the project overview export - which returns the same dataset as the protected report - disclosing customer names, project names, currency, budget type, and aggregate totals across all customers. Actual financial figures remain protected in the export template.
Affected products
- Kimai Kimai: before 2.64.0 (fixed in 2.64.0)
Published 2026-08-26. Last modified 2026-08-31.