CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2026-80201: kimai 0 to before 2.53.0

CVE-2026-80201. CVSS 3.1 base score 2.0 (LOW, Vendor/CNA). EPSS 0.00255 (percentile 0.15671), scored 2026-10-06.

Affected technology

kimai · 0 to before 2.53.0
kimai

Description’s affected range: before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · High privileges required · Passive user interaction

What an attacker can do

Attackers with template creation permissions can embed these method calls in invoice templates to leak hashed API tokens in rendered invoice output. Vendor/CNA’s CVSS 4.0 assessment (base score 2.0/10) rates confidentiality impact as low; integrity and availability impact as none.

Published

CWE
CWE-94
CCR priority
8.1 /100 (P5)
CVSS 3.1
2.0 /10 · CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N · Vendor/CNA
EPSS
0.00255 · percentile 0.15738 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-80201.html