---
id: CVE-2026-80198
title: >-
  Kimai versions before 2.56.0 fail to restrict the config() Twig function in
  sandboxed invoice and export templates, allowing administrators to access
  arbitrary configuration keys
summary: >-
  Kimai versions before 2.56.0 fail to restrict the config() Twig function in
  sandboxed invoice and export templates, allowing administrators to access
  arbitrary configuration keys. Attackers with admin privileges can upload
  malicious temp…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-693
published: '2026-08-26'
updated: '2026-08-28'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80198'
references:
  - url: 'https://github.com/kimai/kimai/security/advisories/GHSA-vrqv-52x7-rm4v'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/kimai-before-2.56.0-information-disclosure-via-config-twig-function
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00432
epssPercentile: 0.3488
ingestedAt: '2026-08-29T21:42:34.400Z'
---

## Overview

Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys. Attackers with admin privileges can upload malicious templates to exfiltrate server-wide secrets including LDAP bind passwords and SAML private keys into invoice or export documents accessible to lower-privileged users.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
