Junglewise Threat Intelligence

CVE-2026-80196: Kimai authentication bypass in password reset link

CVE-2026-80196 · Severity: high · CVSS 7.5 · Published 2026-08-26

Technologies: kimai/kimai (Packagist), Kimai. Vendors: Packagist, Kimai.

Executive brief

Kimai is a time tracking and project management application used by organizations to manage employee hours and project billing. A flaw in its password reset mechanism allows attackers who intercept or cache a password reset link to log in to user accounts multiple times even after the legitimate user has changed their password, effectively bypassing the password change security measure.

Technical details

The vulnerability exists in Kimai's LoginLink signature generation for password reset URLs, which covers only the user ID and not the password hash. After a user successfully resets their password via a link, that same link remains valid for up to 2 additional uses within a 1-hour window due to Symfony's LoginLinkHandler allowing 3 total uses per link. An attacker who intercepts the reset link can authenticate as the user even after the legitimate user has changed their password, bypassing the forced-password-reset wizard on subsequent uses. The fix involves including the password hash in the signature generation, which invalidates the link once the user changes their password. No authentication is required to use an intercepted link; the attack is purely network-based.

Affected products

  • Kimai Kimai before 2.58.0

Timeline

  • 2026-05-27: disclosed: GitHub Security Advisory GHSA-m492-gv72-xvxj published
  • 2026-08-26: advisory: CVE-2026-80196 published on NVD
  • 2026: patched: Fix released in Kimai 2.58.0

References

Related threats