the password in Kimai 2.58.0 did not always invalidate reset links, a serious vulnerability that could keep a link active even after credentials were updated. The entry CVE-2026-80196 describes an authentication bypass with a high CVSS 4.0 score of 8.7, when a link was leaked.

The issue affects Kimai versions up to 2.57.0 and affects OnPremise and Cloud installations, according to Kimai's official security bulletin. The company rated the severity low in the original GHSA, but the newer CVE lists the risk as high because the leaked link could offer a fully authenticated session.
See also: CVE-2026-21962: Critical Oracle WebLogic vulnerability being exploited
Changing the password in Kimai 2.58.0
The reason lies in the way the LoginLink. The signature was based only on the user's internal identifier and did not include the hash of the current password, username, or email. Thus, changing the password did not automatically invalidate the old link.
The technical analysis in the GitHub Security Advisory states that Symfony's mechanism allowed up to three total uses of the same link. After the first legitimate use and password change, the link could be used up to two more times within a one-hour window.

The scenario did not require an attack on the server. It was enough to copy the link from a corporate email system, shared inbox, synchronized browsing history, or proxy and WAF logs. The CVE-2026-80196 entry notes that an attacker could log in as the user even after the user changed their password.
The solution after changing the password
The fixed version embeds the password hash in the login link signature. With this change, any password change immediately invalidates a previous link. The same logic applies to login links generated on demand by administrators via the command line.
Kimai 2.58.0 is the minimum fix release for this issue, and administrators can install a newer version if available. This upgrade is particularly important in environments where restore links are subject to automated security checks or stored in centralized logging systems.
See also: TranslatePress Vulnerability: Critical Privilege Escalation in WordPress
The practical consequence depends on whether the link was disclosed to a third party. It does not appear that the vulnerability allowed arbitrary creation of new links without account access or a recovery process. However, maintaining validity after a password change weakened a key incident response measure.
Infrastructure managers are asked to record the Kimai version, hosting model, and any integrations with authentication or email services. Gathering this information makes it easier to assess whether a link could have been cached, forwarded, or automatically opened by a security service.
The GHSA was published by Kimai maintainers on May 27, 2026, while the CVE appeared later on August 25. The difference in timestamps explains why teams may encounter the GHSA technical description first and then the entry with the CVE number. Both sources lead to the same fixed version.
The initial low severity rating was primarily due to the conditions for the link leak and the limited time window. The newer high risk classification highlights the effect: an old link can override the expectation that changing the password terminates access. For organizations with strict revocation procedures, this difference should be reflected in the risk assessment.

Recommendations for administrators
Teams using Kimai should check the version of each installation and upgrade to 2.58.0 or later. After updating, it is advisable to examine the logs for unusual uses of reset links, as well as the paths where URLs are stored by mail scanners, proxies, and WAFs.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
If you suspect that a link was leaked before the upgrade, changing the password alone is not enough on older versions. You need to install the patched version and check active sessions, along with reviewing account permissions. The SecNews technical team also recommends limiting the exposure of sensitive URLs to logging systems.

The case illustrates why account recovery mechanisms need to be tied to the current state of credentials. Kimai 2.58.0 closes the gap, but secure operation requires checking old links and points from which they could have been leaked.
See also: miniOrange SAML: Critical login bypass threatens WordPress
