logo

Critical Kimai Docker Flaw Lets Hackers Forge Cookies and Hijack Admin Accounts

ID: 7c2015d3-b939-517c-a561-5c5563665690

STIX ID: report--7c2015d3-b939-517c-a561-5c5563665690

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Tamilselvan

...
...

A critical vulnerability (CVE-2026-52824) was disclosed in the official Kimai Docker image where a hardcoded default APP_SECRET (`change_this_to_something_unique`) allowed unauthenticated attackers to forge Symfony HMAC-signed tokens (remember-me cookies, login links, password resets, CSRF tokens) and take over user accounts including super_admin. The issue affected Docker and the .env.dist template; Kimai 2.58.0 mitigates the flaw by auto-generating and persisting a random APP_SECRET at startup and removing the insecure default. Administrators should upgrade immediately or set a unique high-entropy APP_SECRET and enforce 2FA for admin accounts as interim mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.