
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23626 is an authenticated Server-Side Template Injection (SSTI) vulnerability in Kimai, a web-based multi-user time-tracking application. The flaw exists in Kimai's export functionality, where the Twig sandbox uses an overly permissive DefaultPolicy that allows arbitrary method calls on objects in the template context. All versions prior to 2.46.0 are affected. The vulnerability was discovered on 2026-01-05 and publicly disclosed on 2026-01-18 via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 6.8 (Medium) (GitHub Advisory).
The root cause is classified as CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine). The vulnerable code resides in src/Twig/SecurityPolicy/ExportPolicy.php, which includes DefaultPolicy — a class whose checkSecurity(), checkMethodAllowed(), and checkPropertyAllowed() methods are entirely empty, imposing no restrictions on Twig tags, filters, functions, or method calls. An attacker with export permissions and filesystem access to the Kimai server can place a malicious .pdf.twig template in /opt/kimai/var/export/, then trigger it via the export endpoint (/en/export/data). The template can call methods such as app.request.server.get('APP_SECRET'), app.session.get('_security_secured_area'), and entry.user.password to extract sensitive data. Exploitation requires a valid account with export permissions (typically ROLE_ADMIN, ROLE_SUPER_ADMIN, or ROLE_TEAMLEAD) and the ability to write files to the server's export template directory (GitHub Advisory).
Successful exploitation allows an authenticated attacker to extract highly sensitive data including environment variables (APP_SECRET, DATABASE_URL), bcrypt password hashes for all users, serialized session tokens, and CSRF tokens. The extracted APP_SECRET can be used to forge Symfony login links for any user account, enabling full account takeover without knowing the target's password — this is why the CVSS scope is rated as "Changed." The DATABASE_URL exposes direct database credentials, and harvested password hashes are subject to offline cracking. The combined impact represents a near-complete compromise of application confidentiality and user session security (GitHub Advisory).
A detailed proof-of-concept exploit script (ssti_exploit.py) and malicious Twig template are publicly documented in the GitHub Security Advisory, making this vulnerability straightforward to reproduce for anyone with the required access. No evidence of in-the-wild exploitation has been reported as of the time of disclosure. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.022% (0.000220), indicating a currently low probability of widespread exploitation (GitHub Advisory).
ROLE_ADMIN, ROLE_SUPER_ADMIN, or ROLE_TEAMLEAD)./opt/kimai/var/export/ssti-extract.pdf.twig containing Twig expressions such as {{ app.request.server.get("APP_SECRET") }}, {{ app.session.get("_security_secured_area") }}, and {{ entry.user.password }}./en/export/data with the renderer parameter set to ssti-extract.pdf.twig and appropriate state/filter parameters to include timesheet entries.pdftotext to extract the rendered plaintext, which will contain APP_SECRET, DATABASE_URL, all user bcrypt password hashes, serialized session tokens, and CSRF tokens.APP_SECRET to forge Symfony login links for any user account, or crack the bcrypt hashes offline to obtain plaintext passwords for lateral movement (GitHub Advisory)./en/export/data with a renderer parameter referencing non-standard or unexpected .pdf.twig template names; outbound connections from the Kimai server to unknown hosts following export activity..twig files in /opt/kimai/var/export/ (e.g., ssti-extract.pdf.twig) not matching legitimate export templates; new or modified files in the Kimai var/ directory.pdftotext or similar tools being run on the host following export activity (GitHub Advisory).Upgrade Kimai to version 2.46.0 or later, which replaces the permissive DefaultPolicy with a hardened policy that restricts method calls on sensitive objects such as Request, Session, and User in export templates. As an interim workaround, restrict export permissions to the minimum number of trusted users and audit who holds ROLE_ADMIN, ROLE_SUPER_ADMIN, or ROLE_TEAMLEAD roles. Additionally, monitor the /opt/kimai/var/export/ directory for unauthorized template files and review export activity logs for anomalous template usage. The fix was merged in pull request #5757 and is available in the 2.46.0 release (GitHub Advisory, Kimai PR #5757).
The vulnerability was reported by security researcher Mahammad Huseynkhanli and acknowledged by Kimai maintainer kevinpapst, who published the advisory and released the patch on the same day (2026-01-18). The fix was described as adding "security checks to prevent access to sensitive data in twig export templates" and hardening invoice template sandboxes. Coverage appeared on security aggregators including Vulners, VulDB, and INCIBE-CERT shortly after disclosure (GitHub Advisory, Kimai PR #5757).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."