API Token Exposure in Kimai Due to Invoice Template Vulnerabilities
CVE-2026-80201

2LOW

Key Information:

Vendor

Kimai

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-80201?

Kimai versions prior to 2.53.0 are susceptible to a vulnerability that allows attackers with template creation permissions to call sensitive user methods in the Twig invoice template sandbox. This oversight presents the potential for malicious actors to embed method calls within invoice templates, leading to the unintentional disclosure of hashed API tokens in the rendered output of invoices. Proper security measures and timely updates are essential to mitigate this risk and protect sensitive information.

Affected Version(s)

kimai 0 < 2.53.0

kimai 2.53.0

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hett-patell
.