CVE-2026-23626: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-23626 is an authenticated Server-Side Template Injection (SSTI) vulnerability in Kimai, a web-based multi-user time-tracking application. The flaw exists in Kimai's export functionality, where the Twig sandbox uses an overly permissive DefaultPolicy that allows arbitrary method calls on objects in the template context. All versions prior to 2.46.0 are affected. The vulnerability was discovered on 2026-01-05 and publicly disclosed on 2026-01-18 via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 6.8 (Medium) (GitHub Advisory).

Technical details

The root cause is classified as CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine). The vulnerable code resides in src/Twig/SecurityPolicy/ExportPolicy.php, which includes DefaultPolicy — a class whose checkSecurity(), checkMethodAllowed(), and checkPropertyAllowed() methods are entirely empty, imposing no restrictions on Twig tags, filters, functions, or method calls. An attacker with export permissions and filesystem access to the Kimai server can place a malicious .pdf.twig template in /opt/kimai/var/export/, then trigger it via the export endpoint (/en/export/data). The template can call methods such as app.request.server.get('APP_SECRET'), app.session.get('_security_secured_area'), and entry.user.password to extract sensitive data. Exploitation requires a valid account with export permissions (typically ROLE_ADMIN, ROLE_SUPER_ADMIN, or ROLE_TEAMLEAD) and the ability to write files to the server's export template directory (GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker to extract highly sensitive data including environment variables (APP_SECRET, DATABASE_URL), bcrypt password hashes for all users, serialized session tokens, and CSRF tokens. The extracted APP_SECRET can be used to forge Symfony login links for any user account, enabling full account takeover without knowing the target's password — this is why the CVSS scope is rated as "Changed." The DATABASE_URL exposes direct database credentials, and harvested password hashes are subject to offline cracking. The combined impact represents a near-complete compromise of application confidentiality and user session security (GitHub Advisory).

Exploitability

A detailed proof-of-concept exploit script (ssti_exploit.py) and malicious Twig template are publicly documented in the GitHub Security Advisory, making this vulnerability straightforward to reproduce for anyone with the required access. No evidence of in-the-wild exploitation has been reported as of the time of disclosure. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.022% (0.000220), indicating a currently low probability of widespread exploitation (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Kimai instance running version ≤ 2.45.0 and obtain valid credentials for an account with export permissions (ROLE_ADMIN, ROLE_SUPER_ADMIN, or ROLE_TEAMLEAD).
  2. Deploy malicious template: Using filesystem access to the Kimai server (e.g., via Docker exec or SSH), write a malicious Twig template to /opt/kimai/var/export/ssti-extract.pdf.twig containing Twig expressions such as {{ app.request.server.get("APP_SECRET") }}, {{ app.session.get("_security_secured_area") }}, and {{ entry.user.password }}.
  3. Authenticate: Log in to the Kimai web interface using the privileged account, extracting the CSRF token from the login page for use in subsequent requests.
  4. Trigger the export: Send a POST request to /en/export/data with the renderer parameter set to ssti-extract.pdf.twig and appropriate state/filter parameters to include timesheet entries.
  5. Extract data from PDF: Save the returned PDF response and use pdftotext to extract the rendered plaintext, which will contain APP_SECRET, DATABASE_URL, all user bcrypt password hashes, serialized session tokens, and CSRF tokens.
  6. Escalate access: Use the extracted APP_SECRET to forge Symfony login links for any user account, or crack the bcrypt hashes offline to obtain plaintext passwords for lateral movement (GitHub Advisory).

Indicators of compromise

  • Network: Unusual POST requests to /en/export/data with a renderer parameter referencing non-standard or unexpected .pdf.twig template names; outbound connections from the Kimai server to unknown hosts following export activity.
  • File System: Presence of unexpected .twig files in /opt/kimai/var/export/ (e.g., ssti-extract.pdf.twig) not matching legitimate export templates; new or modified files in the Kimai var/ directory.
  • Logs: Kimai application logs showing export requests referencing custom template names; Symfony/PHP error logs containing SSTI-related rendering exceptions or unusual method call traces.
  • Process: Unexpected child processes spawned by the PHP/web server process; evidence of pdftotext or similar tools being run on the host following export activity (GitHub Advisory).

Mitigation and workarounds

Upgrade Kimai to version 2.46.0 or later, which replaces the permissive DefaultPolicy with a hardened policy that restricts method calls on sensitive objects such as Request, Session, and User in export templates. As an interim workaround, restrict export permissions to the minimum number of trusted users and audit who holds ROLE_ADMIN, ROLE_SUPER_ADMIN, or ROLE_TEAMLEAD roles. Additionally, monitor the /opt/kimai/var/export/ directory for unauthorized template files and review export activity logs for anomalous template usage. The fix was merged in pull request #5757 and is available in the 2.46.0 release (GitHub Advisory, Kimai PR #5757).

Community reactions

The vulnerability was reported by security researcher Mahammad Huseynkhanli and acknowledged by Kimai maintainer kevinpapst, who published the advisory and released the patch on the same day (2026-01-18). The fix was described as adding "security checks to prevent access to sensitive data in twig export templates" and hardening invoice template sandboxes. Coverage appeared on security aggregators including Vulners, VulDB, and INCIBE-CERT shortly after disclosure (GitHub Advisory, Kimai PR #5757).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management