Kimai Docker Flaw Lets Unauthenticated Attackers Forge Cookies and Take Over Accounts
ID: 22730a26-73d3-55b1-b170-50647f68b58b
STIX ID: report--22730a26-73d3-55b1-b170-50647f68b58b
Feed Name: cybersecurityNews.com
A critical vulnerability (CVE-2026-52824) in the official Kimai Docker image used an insecure default APP_SECRET ("change_this_to_something_unique") that could let remote attackers forge HMAC-signed tokens (remember-me cookies, login links, password reset URLs, CSRF tokens) and impersonate or take over accounts including the first super-administrator; the issue affects Kimai ≤2.57.0 and is fixed in 2.58.0 — administrators are urged to upgrade, set a unique high-entropy APP_SECRET, rotate credentials/sessions, review admin accounts, and enable 2FA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
