← Back to overview

Kimai versions prior to 2.56.0 contain a vulnerability where the config() Twig function is not properly restricted within sandboxed invoice and export templates. Administrators can exploit this flaw by uploading malicious templates that call the config() function to access arbitrary server configuration keys. Sensitive data such as LDAP bind passwords and SAML private keys can be exfiltrated into generated invoice or export documents. These documents may then be accessible to lower-privileged users, expanding the exposure of secrets beyond admin-level access. The vulnerability requires admin privileges to exploit, but the resulting data leakage can affect the broader user base and expose critical authentication infrastructure. A fix was introduced in Kimai version 2.56.0. The issue is tracked as CVE-2026-80198 and has been documented in both the GitHub security advisory and VulnCheck advisories. Organizations using Kimai with LDAP or SAML integrations are at particular risk due to the nature of the exposed secrets.

Affected products

  • Kimai

Related CVE's

  • CVE-2026-80198

Categories

  • Data Breach & Exfiltration
  • Enterprise Applications
  • Identity & Access
  • Web Technologies