๐Ÿ” CVE Alert

CVE-2026-52827

UNKNOWN 0.0

Kimai: Two-factor authentication bypass on the Kimai API

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verification but before TOTP completion is accepted by every /api route because config/packages/security.yaml protects the API with IS_AUTHENTICATED and App\API\Authentication\ApiRequestMatcher routes an existing session through the main firewall. A Scheb TwoFactorToken satisfies that access rule, and App\Voter\ApiVoter grants API access to its User, allowing an attacker with a valid account password to use authenticated REST API operations without entering the second factor even though web routes remain blocked. This issue is fixed in version 2.59.0.

CWE CWE-287
Vendor kimai
Product kimai
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for kimai kimai

Be the first to know when new unknown vulnerabilities affecting kimai kimai are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

kimai / kimai
< 2.59.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kimai/kimai/security/advisories/GHSA-v8hx-4vx8-wc96 github.com: https://github.com/kimai/kimai/pull/5957 github.com: https://github.com/kimai/kimai/commit/87c85270a98899e6545108cbb9f41103ec6ea312 github.com: https://github.com/kimai/kimai/releases/tag/2.59.0 kimai.org: https://www.kimai.org/en/security/ghsa-v8hx-4vx8-wc96