Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-52824: Kimai Docker image uses default secret allowing account takeover

CVE-2026-52824 · published 21 days ago
Summary

The official Kimai Docker container before version 2.58.0 ships with a well‑known secret key. If this key isn’t changed, anyone who can reach the site can create fake login cookies and gain access to user accounts that don’t use two‑factor authentication. Update to version 2.58.0 or set a unique secret value when deploying the container.

What to do
  • Update kimai kimai to version 2.58.0.
  • Update kimai kimai/kimai to version 2.58.0.
Affected software
Ecosystem VendorProductAffected versions
– kimai kimai < 2.58.0
composer kimai kimai <= 2.57.0
Fix: upgrade to 2.58.0
Packagist kimai kimai/kimai < 2.58.0
Fix: upgrade to 2.58.0
Original advisory text
Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover
Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces nor rejects that value before Symfony uses it as kernel.secret. An unauthenticated attacker who reaches a deployment that did not override APP_SECRET, knows a username, correctly guesses the account ID associated with that username, and targets an account without active two-factor authentication can forge HMAC-protected authentication artifacts, including KIMAI_REMEMBER cookies and login links, to access the account without its password. The updated entrypoint generates and persists a random secret when no safe operator-provided value exists. This issue is fixed in version 2.58.0.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
8.6 High
Exploitation
1% chance of attack within 30 days
Type
CWE-1188Initialization of a Resource with an Insecure Default
Timeline
Published15 Sep 2026
Updated3 Oct 2026
First seen14 Jul 2026
Track software like this
Free during beta