VYPR

REST API

by Kimai

CVEs (1)

  • CVE-2026-52827higJul 14, 2026
    risk 0.45cvss epss

    ### Summary Two-factor authentication (TOTP) can be fully bypassed for the REST API. The `KIMAI_SESSION` cookie returned in the response to the login request; issued after only the password is verified, before the TOTP step; is already accepted as authenticated by every `/api/*`…