---
id: CVE-2026-80196
title: >-
  Kimai before 2.58.0 contains an authentication bypass vulnerability where
  password reset links remain valid after password changes because the LoginLink
  signature covers only the user id, not the password hash
summary: >-
  Kimai before 2.58.0 contains an authentication bypass vulnerability where
  password reset links remain valid after password changes because the LoginLink
  signature covers only the user id, not the password hash. Attackers who
  intercept or…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-640
vendor: kimai
product: kimai
affected:
  - kimai < 2.58.0
published: '2026-08-26'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:45.393'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80196'
references:
  - url: 'https://github.com/kimai/kimai/security/advisories/GHSA-m492-gv72-xvxj'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/kimai-before-2.58.0-authentication-bypass-via-password-reset-link
    label: disclosure@vulncheck.com
  - url: 'https://github.com/kimai/kimai/security/advisories/GHSA-m492-gv72-xvxj'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-08-26T14:16:58.120574Z'
epss: 0.00535
epssPercentile: 0.43317
ingestedAt: '2026-10-08T16:52:14.726Z'
---

## Overview

Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes because the LoginLink signature covers only the user id, not the password hash. Attackers who intercept or cache a password reset link can use it up to 2 additional times within a 1-hour window to log in as the user even after the legitimate user has changed their password.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
