CVE-2026-80200: Kimai before 2.53.0 Open Redirect via RelayState

Published Aug 25, 2026
·
Updated

Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with IdP access can supply malicious RelayState values to redirect authenticated users to attacker-controlled URLs for credential theft or phishing attacks.

Affected Software

1 affected component
Kimai Kimai<2.53.0

Event History

Aug 25, 2026
CVE Published
via MITRE·11:19 PM
Data Sourced
via MITRE·11:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs access to the identity provider and must be able to supply a malicious RelayState value during the SAML authentication flow. The attack also requires an authenticated user to follow the resulting redirect.

2

Are all Kimai deployments affected?

The issue is in the SAML authentication success handler, so exposure depends on use of SAML authentication. Kimai versions before 2.53.0 are affected.

3

What is the impact of a successful exploit?

The attacker can redirect an authenticated user to an attacker-controlled URL. This can support phishing or credential-theft attempts, but the provided information does not indicate direct confidentiality, integrity, or availability impact to Kimai itself.

4

What should be done to remediate the issue?

Upgrade Kimai to version 2.53.0 or later. If upgrading is not immediately possible, restrict identity-provider access to trusted administrators and users who cannot submit malicious RelayState values.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203