
🚨*CVE* CVE-2026-80201 Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. … https://www.cve.org/CVERecord?id=CVE-2026-80201 ----- Traducción: CVE-2026-80201 Kim… https://infoflow.cloud`
Post summary
This tweet announces that Kimai versions prior to 2.53.0 contain a sandbox bypass allowing admin users to retrieve API tokens through exposed User methods.

