Authentication Bypass in Kimai by Kimai Team
CVE-2026-80196
8.7HIGH
What is CVE-2026-80196?
Kimai versions before 2.58.0 have a vulnerability where password reset links remain valid even after a user changes their password. This flaw arises because the LoginLink signature is linked solely to the user ID, omitting the password hash. As a result, attackers who intercept or cache these password reset links may exploit them to gain unauthorized access, logging in as the user multiple times within a one-hour period even after the legitimate user has updated their password.
Affected Version(s)
kimai 0 < 2.58.0
kimai 2.58.0
