PT-2026-81911 · Kimai · Kimai

·

CVE-2026-80198

·

Published

2026-05-06

·

Updated

2026-08-26

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kimai versions prior to 2.56.0
Description Sandboxed invoice and export templates fail to restrict the config() Twig function, enabling administrators to access arbitrary configuration keys. Users with administrative privileges can upload malicious templates to exfiltrate server-wide secrets, such as LDAP bind passwords and SAML private keys, by embedding them into invoice or export documents that are accessible to users with lower privileges.
Recommendations Update to version 2.56.0 or later.

Exploit

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80198
GHSA-VRQV-52X7-RM4V

Affected Products

Kimai