Kimai versions before 2.58.0 contain an authentication bypass vulnerability tracked as CVE-2026-80196. The flaw exists because the LoginLink signature used in password reset links only covers the user ID and not the password hash. This means that even after a user changes their password, previously issued reset links remain valid. An attacker who intercepts or caches a password reset link can exploit it up to 2 additional times within a 1-hour window. This allows unauthorized login as the affected user despite the legitimate password change. The vulnerability poses a significant risk to user account security and session integrity. A fix has been released in Kimai version 2.58.0. Users are strongly advised to upgrade immediately to mitigate the risk.