CVE-2026-80196
Received Received - Intake

Authentication Bypass in Kimai Due to Weak Password Reset Link Validation

Vulnerability report for CVE-2026-80196, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: VulnCheck

Description

Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes because the LoginLink signature covers only the user id, not the password hash. Attackers who intercept or cache a password reset link can use it up to 2 additional times within a 1-hour window to log in as the user even after the legitimate user has changed their password.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-26
AI Q&A
2026-08-26
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kimai kimai to 2.58.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-640 The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Kimai before 2.58.0 has an authentication bypass flaw where password reset links remain valid even after a user changes their password. The vulnerability occurs because the reset link signature only includes the user ID, not the password hash. Attackers can reuse intercepted or cached links up to two additional times within a one-hour window to log in as the user despite the password change.

Detection Guidance

Check for unusual login activity from password reset links after password changes. Inspect server logs for repeated login attempts using cached or intercepted reset links within a one-hour window. Look for multiple successful logins from the same IP address or user account in quick succession.

Impact Analysis

This vulnerability allows attackers to gain unauthorized access to user accounts by reusing old password reset links. Even if you change your password, attackers can still log in using cached or intercepted links within an hour. This could lead to data theft, unauthorized actions, or account takeover. Exploitation is possible through leaked links in email, browser history, or proxy logs.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, violating confidentiality requirements under GDPR and HIPAA. Organizations using affected Kimai versions may fail to protect personal data adequately, risking regulatory fines and legal consequences. Compliance with data protection standards requires immediate patching to prevent breaches.

Mitigation Strategies

Update Kimai to version 2.58.0 or later immediately. Review and invalidate all active password reset links. Monitor user accounts for unauthorized access attempts. Consider implementing additional logging for password reset link usage.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80196. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart