PT-2026-3401 · Kimai · Kimai

Huseynkhanli

·

Published

2026-01-18

·

Updated

2026-02-18

·

CVE-2026-23626

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kimai versions prior to 2.46.0
Description Kimai is a web-based multi-user time-tracking application. The export functionality utilizes a Twig sandbox with an overly permissive security policy (DefaultPolicy), enabling arbitrary method calls on objects within the template context. An authenticated user possessing export permissions can leverage this to deploy a malicious Twig template, potentially extracting sensitive information. This information includes environment variables, all user password hashes, serialized session tokens, and CSRF tokens.
Recommendations Update to version 2.46.0 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-23626
GHSA-JG2J-2W24-54CG

Affected Products

Kimai