CVE-2026-52827
Kimai: Two-factor authentication bypass on the Kimai API
Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verification but before TOTP completion is accepted by every /api route because config/packages/security.yaml protects the API with IS_AUTHENTICATED and App\API\Authentication\ApiRequestMatcher routes an existing session through the main firewall. A Scheb TwoFactorToken satisfies that access rule, and App\Voter\ApiVoter grants API access to its User, allowing an attacker with a valid account password to use authenticated REST API operations without entering the second factor even though web routes remain blocked. This issue is fixed in version 2.59.0.
| CWE | CWE-287 |
| Vendor | kimai |
| Product | kimai |
| Published | Sep 15, 2026 |
Get instant alerts for kimai kimai
Be the first to know when new unknown vulnerabilities affecting kimai kimai are published โ delivered to Slack, Telegram or Discord.