Improper access control in kimai2 - CVE-2026-80201
Published: April 14, 2026 / Updated: September 14, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the Twig sandbox policy for invoice templates when rendering user-controlled invoice templates. A remote privileged user can embed calls to sensitive User methods in a crafted invoice template to disclose sensitive information.
Only on-premise installations with template upload activated are affected, and user interaction is required because a user must generate an invoice using the malicious template.