PatchSiren cyber security CVE debrief
CVE-2026-80198 kimai CVE debrief
Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys. Attackers with admin privileges can upload malicious templates to exfiltrate server-wide secrets including LDAP bind passwords and SAML private keys into invoice or export documents accessible to lower-privileged users. The CVE record was published on 2026-08-26T05:18:27.380Z and has not been modified since then. The NVD entry is currently Deferred. Administrators and users of Kimai versions before 2.56.0, especially those with administrative privileges, should be aware of the potential for information disclosure via malicious templates. Users with lower privileges who can access invoice or export documents may also be impacted by this vulnerability. Review of server-wide secrets and compensating controls is recommended for exposed systems while remediation is scheduled and verified. Monitoring for suspicious template uploads and implementing asset inventory tracking are also suggested. This vulnerability affects Kimai deployments, particularly those with administrative access to template uploads. Operators and security teams should review the official advisory and CVE record to validate affected scope and vendor guidance. Affected platform users should prioritize updating Kimai to version 2.56.0 or later to restrict the config() Twig function in sandboxed invoice and export templates. Vulnerability management and security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Compensating controls for exposed systems and monitoring for suspicious activity are also recommended while remediation is in progress. Rollback and change windows should be considered for updates. Source tracking and verification of affected scope are crucial for effective remediation. To ensure effective mitigation, it is essential to review server-wide secrets for potential exposure and implement compensating controls for sensitive data access. Additionally, monitoring for suspicious template uploads and implementing asset inventory tracking can help and
- Vendor
- kimai
- Product
- Unknown
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-26
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-26
- Advisory updated
- 2026-08-31
Who should care
Administrators and users of Kimai versions before 2.56.0, especially those with administrative privileges, should be aware of the potential for information disclosure via malicious templates. Users with lower privileges who can access invoice or export documents may also be impacted by this vulnerability. Review of server-wide secrets and compensating controls is recommended for exposed systems while remediation is scheduled and verified. Monitoring for suspicious template uploads and implementing asset inventory tracking are also suggested. This vulnerability affects Kimai deployments, particularly those with administrative access to template uploads. Operators and security teams should review the official advisory and CVE record to validate affected scope and vendor guidance. Affected platform users should prioritize updating Kimai to version 2.56.0 or later to restrict the config() Twig function in sandboxed invoice and export templates. Vulnerability management and security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Compensating controls for exposed systems and monitoring for suspicious activity are also recommended while remediation is in progress. Rollback and change windows should be considered for updates. Source tracking and verification of affected scope are crucial for effective remediation. This vulnerability has a significant impact on the security posture of affected Kimai deployments, requiring prompt attention from administrators and security teams. The CVE record was published on 2026-08-26T05:18:27.380Z and has not been modified since then. The NVD entry is currently Deferred, indicating a need for further review and validation of the vulnerability details. To ensure effective mitigation, it is essential to review server-wide secrets for potential exposure and implement compensating controls for sensitive data access. Additionally, monitoring for suspicious template uploads and implementing asset inventory tracking can help detect and prevent potential exploitation. By taking these steps, administrators and security teams can reduce the risk associated with this vulnerability.
Technical summary
Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators with upload privileges to access arbitrary configuration keys and exfiltrate server-wide secrets, including LDAP bind passwords and SAML private keys, into invoice or export documents accessible to lower-privileged users. This vulnerability has a high CVSS score of 8.7.
Defensive priority
Administrators should prioritize updating Kimai to version 2.56.0 or later to restrict the config() Twig function in sandboxed invoice and export templates, and review server-wide secrets for potential exposure.
Recommended defensive actions
- Update Kimai to version 2.56.0 or later
- Review server-wide secrets for potential exposure
- Restrict access to sensitive configuration keys
- Monitor for suspicious template uploads
- Implement compensating controls for sensitive data access
Evidence notes
The CVE description indicates that Kimai versions before 2.56.0 fail to restrict the config() Twig function, allowing administrators to access arbitrary configuration keys. Attackers with admin privileges can upload malicious templates to exfiltrate server-wide secrets including LDAP bind passwords and SAML private keys into invoice or export documents accessible to lower-privileged users. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-80198 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-80198
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-80198 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80198
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/kimai/kimai/security/advisories/GHSA-vrqv-52x7-rm4v
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/kimai-before-2.56.0-information-disclosure-via-config-twig-function
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.