Open Redirect Vulnerability in Kimai Product by Kimai
CVE-2026-80200
NONE
What is CVE-2026-80200?
The Kimai application prior to version 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler. This flaw allows attackers with access to an Identity Provider (IdP) to manipulate the RelayState POST parameters, which can lead to redirecting authenticated users to malicious external URLs. Such a redirection can be exploited for credential theft or phishing campaigns, thereby compromising sensitive user information. It is essential for users of Kimai to upgrade to the latest version to mitigate this risk.
Affected Version(s)
kimai 0 < 2.53.0
kimai 2.53.0
