Open Redirect Vulnerability in Kimai Product by Kimai
CVE-2026-80200

NONE

Key Information:

Vendor

Kimai

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-80200?

The Kimai application prior to version 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler. This flaw allows attackers with access to an Identity Provider (IdP) to manipulate the RelayState POST parameters, which can lead to redirecting authenticated users to malicious external URLs. Such a redirection can be exploited for credential theft or phishing campaigns, thereby compromising sensitive user information. It is essential for users of Kimai to upgrade to the latest version to mitigate this risk.

Affected Version(s)

kimai 0 < 2.53.0

kimai 2.53.0

References

CVSS V4

Score:
Severity:
NONE
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

morimori-dev
.