PT-2026-81913 · Kimai · Kimai

·

CVE-2026-80200

·

Published

2026-04-14

·

Updated

2026-08-26

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kimai versions prior to 2.53.0
Description An open redirect issue exists in the SAML authentication success handler. The system accepts unvalidated RelayState POST parameters as redirect destinations, allowing attackers with Identity Provider (IdP) access to redirect authenticated users to malicious URLs. This can be used to facilitate phishing attacks or credential theft.
Recommendations Update to version 2.53.0 or later.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80200
GHSA-3JP4-MHH4-GCGR

Affected Products

Kimai