Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes because the LoginLink signature covers only the user id, not the password hash. Attackers who intercept or cache a password reset link can use it up to 2 additional times within a 1-hour window to log in as the user even after the legitimate user has changed their password. | |
| Title | Kimai before 2.58.0 Authentication Bypass via Password Reset Link | |
| First Time appeared |
Kimai
Kimai kimai |
|
| Weaknesses | CWE-640 | |
| CPEs | cpe:2.3:a:kimai:kimai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kimai
Kimai kimai |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T23:19:03.107Z
Reserved: 2026-08-25T23:14:37.730Z
Link: CVE-2026-80196
No data.
No data.
No data.
OpenCVE Enrichment
No data.