Description
Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verification but before TOTP completion is accepted by every /api route because config/packages/security.yaml protects the API with IS_AUTHENTICATED and App\API\Authentication\ApiRequestMatcher routes an existing session through the main firewall. A Scheb TwoFactorToken satisfies that access rule, and App\Voter\ApiVoter grants API access to its User, allowing an attacker with a valid account password to use authenticated REST API operations without entering the second factor even though web routes remain blocked. This issue is fixed in version 2.59.0.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Bypass of Two‑Factor Authentication on API
Action: Apply patch
AI Analysis

Impact

Kimai, an open‑source time tracking application, allows attackers to authenticate to the REST API by supplying only a valid password. During the period between password verification and TOTP completion, the KIMAI_SESSION cookie is accepted for all /api routes because the configuration protects the API with IS_AUTHENTICATED and the session is routed through the main firewall. The TwoFactorToken satisfies this rule, and the ApiVoter grants access to the user. Consequently an attacker with a legitimate account password can perform full API operations without providing the second factor, even though web routes still require TOTP. This flaw is an unrestricted API access that can lead to data exfiltration, manipulation, or escalation of privileges.

Affected Systems

All Kimai installations running any version prior to 2.59.0 are affected. The vulnerability is present in the kimai:kimai product and is mitigated only by upgrading to version 2.59.0 or later.

Risk and Exploitability

The CVSS score of 7.1 classifies the weakness as high severity. The EPSS score of less than 1% indicates that attacks against this flaw are currently considered unlikely, and it is not listed in CISA KEV catalog. The likely attack vector is network access to the REST API; an attacker must possess or steal a valid user password to exploit it. Once authenticated, the attacker can bypass the second factor and use any authorized API endpoint, potentially compromising data confidentiality and integrity.

Generated by OpenCVE AI on September 17, 2026 at 17:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kimai to version 2.59.0 or later.
  • Configure the API firewall to require TOTP authentication for all endpoints.
  • Invalidate existing session cookies for all users to force reauthentication with two‑factor.
  • Monitor API logs for unexpected activity and revoke credentials for any compromised accounts.

Generated by OpenCVE AI on September 17, 2026 at 17:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-v8hx-4vx8-wc96 Kimai: Pre-2FA KIMAI_SESSION cookie grants full authenticated REST API access, bypassing TOTP
History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Kimai
Kimai kimai
Vendors & Products Kimai
Kimai kimai

Tue, 15 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verification but before TOTP completion is accepted by every /api route because config/packages/security.yaml protects the API with IS_AUTHENTICATED and App\API\Authentication\ApiRequestMatcher routes an existing session through the main firewall. A Scheb TwoFactorToken satisfies that access rule, and App\Voter\ApiVoter grants API access to its User, allowing an attacker with a valid account password to use authenticated REST API operations without entering the second factor even though web routes remain blocked. This issue is fixed in version 2.59.0.
Title Kimai: Two-factor authentication bypass on the Kimai API
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T16:08:20.250Z

Reserved: 2026-06-08T18:11:06.662Z

Link: CVE-2026-52827

cve-icon Vulnrichment

Updated: 2026-09-16T16:08:16.791Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:09.993

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-52827

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses