CVE-2026-28685 - Kimai: API invoice endpoint missing customer-level access control (IDOR)

CVE-2026-28685 - Kimai: API invoice endpoint missing customer-level access control (IDOR)

CVE ID : CVE-2026-28685 Published : March 6, 2026, 5:16 a.m. | 35 minutes ago Description : Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0,

CVE Details

Published
March 6, 2026