securityonline.info 7/20/2026, 2:01:46 AM · external

CVE-2026-52824: Default Docker Secret in Kimai Enables Account Takeover of Super Admin Accounts

CVE-2026-52824: Default Docker Secret in Kimai Enables Account Takeover of Super Admin Accounts
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability, CVE-2026-52824, affects the Kimai time-tracking app due to a default APP_SECRET in its Docker image, enabling cookie forgery and account takeover, notably for super_admin accounts. The CVSS score is 9.1, and all versions up to 2.57.0 are impacted. Users are advised to update to version 2.58.0, which corrects the issue by generating a unique secret. Active two-factor authentication (2FA) can also prevent unauthorized access. Although a proof-of-concept exists, no real-world exploitation has been reported.

View Primary Source Via securityonline.info

Article by CyberSIXT