Protection Mechanism Failure Affecting kimai/kimai package, versions <2.56.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-KIMAIKIMAI-16438203
  • published7 May 2026
  • disclosed6 May 2026
  • creditfg0x0

Introduced: 6 May 2026

New CVE NOT AVAILABLE CWE-693  (opens in a new tab)

How to fix?

Upgrade kimai/kimai to version 2.56.0 or higher.

Overview

Affected versions of this package are vulnerable to Protection Mechanism Failure via the config function. An attacker can access sensitive server-wide secrets, such as LDAP bind passwords and SAML private keys, by uploading a malicious template and causing it to be rendered by another user. This is only exploitable if LDAP or SAML is configured and a user other than the SUPER_ADMIN renders an invoice or export using the malicious template.

CVSS Base Scores

version 4.0
version 3.1