SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-80200

MEDIUM · CVSS 4.7 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Kimai versions prior to 2.53.0 are susceptible to an open redirect vulnerability in the SAML authentication success handler, allowing attackers with IdP access to manipulate unvalidated RelayState POST parameters. This could lead to the redirection of authenticated users to malicious URLs, posing a risk of credential theft or phishing attacks. Organizations utilizing Kimai for SAML authentication should prioritize addressing this vulnerability to safeguard user credentials and prevent potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-80200
Severity
MEDIUM
CVSS
4.7
EPSS
0.29%

Original NVD Description

Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with IdP access can supply malicious RelayState values to redirect authenticated users to attacker-controlled URLs for credential theft or phishing attacks.