Impact
Kimai versions prior to 2.58.0 contain a weakness that allows an attacker to use password reset links that remain valid after a user changes their password. The reset link signature only covers the user identifier and does not include the password hash, enabling an attacker who intercepts or caches the link to log in as the target user up to two additional times within a one‑hour window, even after the user has altered their credentials. This flaw effectively grants an attacker unauthorized access to the victim’s account and any data or functions available to that account, without requiring any further credentials. The weakness is aligned with CWE‑640, which describes authentication bypass through incomplete token validation.
Affected Systems
The issue affects the Kimai time‑tracking application from the vendor kimai:kimai. Any installation running a version earlier than 2.58.0 is susceptible.
Risk and Exploitability
The CVSS score of 8.7 indicates a high‑severity bug. Although the EPSS score is not available, the flaw allows remote exploitation simply by using a valid reset link, which an attacker may obtain through social engineering, phishing, or e‑mail interception. The vulnerability is not listed in the CISA KEV catalog, so no publicly available exploits are currently documented, but the high CVSS and simple attack path make it a serious risk to deployed systems.
OpenCVE Enrichment