Summary
CVE-2026-80196 is an authentication bypass vulnerability in Kimai, an open-source time-tracking application, affecting all versions up to and including 2.57.0. The flaw allows a password reset ("login") link to remain valid and reusable even after the target user has changed their password, letting an attacker who obtained the link authenticate as that user. The issue is rated HIGH severity.
Technical details
- Root cause: the HMAC signature generated for password reset/login links covers only the user’s
id, and excludes thepasswordhash,username, oremail. - Because the password hash is not part of the signed data, changing a password does not invalidate previously issued reset links.
- The link configuration additionally allows
max_uses: 3, and a session flag that should mark the link as consumed is cleared after first use, permitting up to 2 additional authentications within a 1-hour window. - The same weakness affects admin-generated login links created via Kimai’s
UserLoginLinkCommand. - Attack vector: network-based, requires no authentication or user interaction — an attacker who intercepts, caches, or otherwise obtains a valid reset link can use it to log in as the victim, including after the victim has reset their password.
- Impact: unauthorized authentication as the targeted user (confidentiality impact), potentially enabling full account takeover.
Affected software
- Kimai versions <= 2.57.0 (all versions prior to 2.58.0)
Severity
- CVSS v4.0: 8.7 (HIGH) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N - CVSS v3.1: 7.5 (HIGH) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Upgrade Kimai to version 2.58.0 or later, which incorporates the password hash into the login-link signature so that existing links expire immediately upon a password change.
- If immediate patching is not possible: treat any previously issued password reset or admin login links as compromised, revoke active user sessions where possible, and instruct users to avoid reusing or sharing reset links; monitor authentication logs for repeated logins via reset-link tokens.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Named response header (
set-cookie):KIMAI_SESSION= - Raw response body:
localStorage.getItem("kimai_profile")/localStorage.setItem("kimai_profile"),<meta name="apple-mobile-web-app-title" content="Kimai">

