Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-52824: Kimai Docker image uses default secret allowing account takeover
CVE-2026-52824 · published 21 days ago
Summary
The official Kimai Docker container before version 2.58.0 ships with a well‑known secret key. If this key isn’t changed, anyone who can reach the site can create fake login cookies and gain access to user accounts that don’t use two‑factor authentication. Update to version 2.58.0 or set a unique secret value when deploying the container.
What to do
- Update kimai kimai to version 2.58.0.
- Update kimai kimai/kimai to version 2.58.0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | kimai | kimai | < 2.58.0 |
| composer | kimai | kimai |
<= 2.57.0 Fix: upgrade to 2.58.0
|
| Packagist | kimai | kimai/kimai |
< 2.58.0 Fix: upgrade to 2.58.0
|
Original advisory text
Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover
Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces nor rejects that value before Symfony uses it as kernel.secret. An unauthenticated attacker who reaches a deployment that did not override APP_SECRET, knows a username, correctly guesses the account ID associated with that username, and targets an account without active two-factor authentication can forge HMAC-protected authentication artifacts, including KIMAI_REMEMBER cookies and login links, to access the account without its password. The updated entrypoint generates and persists a random secret when no safe operator-provided value exists. This issue is fixed in version 2.58.0.
References
- https://github.com/kimai/kimai/security/advisories/GHSA-jr9p-4h4j-6c58 Vendor Advisory
- https://github.com/advisories/GHSA-jr9p-4h4j-6c58
- https://github.com/kimai/kimai Product
- https://github.com/kimai/kimai/commit/31a8f887a5cda517db7b4320a7ad997c87d08601 Patch
- https://github.com/kimai/kimai/pull/5952 Patch
- https://github.com/kimai/kimai/releases/tag/2.58.0 URL
- https://www.kimai.org/en/security/ghsa-jr9p-4h4j-6c58 URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52824... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-52824 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
8.6
High
Type
CWE-1188Initialization of a Resource with an Insecure Default
Timeline
Published15 Sep 2026
Updated3 Oct 2026
First seen14 Jul 2026
Sources
GHSA-jr9p-4h4j-6c58 · GHSA
CVE-2026-52824 · NVD
GHSA-jr9p-4h4j-6c58 · OSV
CVE-2026-52824 · MITRE
CVE-2026-52824 · OSV
Track software like this
Free during beta