Protection Mechanism Failure in kimai2 - CVE-2026-80198
Published: April 28, 2026 / Updated: September 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures in the config() Twig function within invoice/export templates. A remote user can bypass implemented security restrictions and gain access to sensitive information on the system.