logo

Kimai Docker Flaw Lets Unauthenticated Attackers Forge Cookies and Take Over Accounts

ID: 22730a26-73d3-55b1-b170-50647f68b58b

STIX ID: report--22730a26-73d3-55b1-b170-50647f68b58b

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Abinaya

...
...

A critical vulnerability (CVE-2026-52824) in the official Kimai Docker image used an insecure default APP_SECRET ("change_this_to_something_unique") that could let remote attackers forge HMAC-signed tokens (remember-me cookies, login links, password reset URLs, CSRF tokens) and impersonate or take over accounts including the first super-administrator; the issue affects Kimai ≤2.57.0 and is fixed in 2.58.0 — administrators are urged to upgrade, set a unique high-entropy APP_SECRET, rotate credentials/sessions, review admin accounts, and enable 2FA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.