HomeSecurityKimai: Changing the password did not invalidate the reset links

Kimai: Changing the password did not invalidate the reset links

the password in Kimai 2.58.0 did not always invalidate reset links, a serious vulnerability that could keep a link active even after credentials were updated. The entry CVE-2026-80196 describes an authentication bypass with a high CVSS 4.0 score of 8.7, when a link was leaked.

Kimai 2.58.0 restore link vulnerability

The issue affects Kimai versions up to 2.57.0 and affects OnPremise and Cloud installations, according to Kimai's official security bulletin. The company rated the severity low in the original GHSA, but the newer CVE lists the risk as high because the leaked link could offer a fully authenticated session.

See also: CVE-2026-21962: Critical Oracle WebLogic vulnerability being exploited

Changing the password in Kimai 2.58.0

The reason lies in the way the LoginLink. The signature was based only on the user's internal identifier and did not include the hash of the current password, username, or email. Thus, changing the password did not automatically invalidate the old link.

The technical analysis in the GitHub Security Advisory states that Symfony's mechanism allowed up to three total uses of the same link. After the first legitimate use and password change, the link could be used up to two more times within a one-hour window.

Kimai password reset link

The scenario did not require an attack on the server. It was enough to copy the link from a corporate email system, shared inbox, synchronized browsing history, or proxy and WAF logs. The CVE-2026-80196 entry notes that an attacker could log in as the user even after the user changed their password.

The solution after changing the password

The fixed version embeds the password hash in the login link signature. With this change, any password change immediately invalidates a previous link. The same logic applies to login links generated on demand by administrators via the command line.

Kimai 2.58.0 is the minimum fix release for this issue, and administrators can install a newer version if available. This upgrade is particularly important in environments where restore links are subject to automated security checks or stored in centralized logging systems.

See also: TranslatePress Vulnerability: Critical Privilege Escalation in WordPress

The practical consequence depends on whether the link was disclosed to a third party. It does not appear that the vulnerability allowed arbitrary creation of new links without account access or a recovery process. However, maintaining validity after a password change weakened a key incident response measure.

Infrastructure managers are asked to record the Kimai version, hosting model, and any integrations with authentication or email services. Gathering this information makes it easier to assess whether a link could have been cached, forwarded, or automatically opened by a security service.

The GHSA was published by Kimai maintainers on May 27, 2026, while the CVE appeared later on August 25. The difference in timestamps explains why teams may encounter the GHSA technical description first and then the entry with the CVE number. Both sources lead to the same fixed version.

The initial low severity rating was primarily due to the conditions for the link leak and the limited time window. The newer high risk classification highlights the effect: an old link can override the expectation that changing the password terminates access. For organizations with strict revocation procedures, this difference should be reflected in the risk assessment.

Kimai update for protection

Recommendations for administrators

Teams using Kimai should check the version of each installation and upgrade to 2.58.0 or later. After updating, it is advisable to examine the logs for unusual uses of reset links, as well as the paths where URLs are stored by mail scanners, proxies, and WAFs.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

If you suspect that a link was leaked before the upgrade, changing the password alone is not enough on older versions. You need to install the patched version and check active sessions, along with reviewing account permissions. The SecNews technical team also recommends limiting the exposure of sensitive URLs to logging systems.

Kimai password change and reset links

The case illustrates why account recovery mechanisms need to be tied to the current state of credentials. Kimai 2.58.0 closes the gap, but secure operation requires checking old links and points from which they could have been leaked.

See also: miniOrange SAML: Critical login bypass threatens WordPress

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS