#VU125949 Improper access control in kimai2
Published: April 14, 2026
kimai2
Kevin Papst
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the Twig sandbox policy for invoice templates when rendering user-controlled invoice templates. A remote privileged user can embed calls to sensitive User methods in a crafted invoice template to disclose sensitive information.
Only on-premise installations with template upload activated are affected, and user interaction is required because a user must generate an invoice using the malicious template.