Authentication Bypass in Kimai by Kimai Team
CVE-2026-80196

8.7HIGH

Key Information:

Vendor

Kimai

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-80196?

Kimai versions before 2.58.0 have a vulnerability where password reset links remain valid even after a user changes their password. This flaw arises because the LoginLink signature is linked solely to the user ID, omitting the password hash. As a result, attackers who intercept or cache these password reset links may exploit them to gain unauthorized access, logging in as the user multiple times within a one-hour period even after the legitimate user has updated their password.

Affected Version(s)

kimai 0 < 2.58.0

kimai 2.58.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AzureADTrent
.