Critical Kimai Docker Flaw Lets Hackers Forge Cookies and Hijack Admin Accounts
ID: 7c2015d3-b939-517c-a561-5c5563665690
STIX ID: report--7c2015d3-b939-517c-a561-5c5563665690
Feed Name: Cyber Press
A critical vulnerability (CVE-2026-52824) was disclosed in the official Kimai Docker image where a hardcoded default APP_SECRET (`change_this_to_something_unique`) allowed unauthenticated attackers to forge Symfony HMAC-signed tokens (remember-me cookies, login links, password resets, CSRF tokens) and take over user accounts including super_admin. The issue affected Docker and the .env.dist template; Kimai 2.58.0 mitigates the flaw by auto-generating and persisting a random APP_SECRET at startup and removing the insecure default. Administrators should upgrade immediately or set a unique high-entropy APP_SECRET and enforce 2FA for admin accounts as interim mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
