PKSA-j5f5-11n1-y3zr Security Advisory
-
[MEDIUM] Kimai's API invoice endpoint missing customer-level access control (IDOR)
PKSA-j5f5-11n1-y3zr CVE-2026-28685 GHSA-v33r-r6h2-8wr7
Affected package: kimai/kimai
Affected version: <=2.50.0
Reported by:
GitHub