A critical vulnerability, CVE-2026-52824, affects the Kimai time-tracking app due to a default APP_SECRET in its Docker image, enabling cookie forgery and account takeover, notably for super_admin accounts. The CVSS score is 9.1, and all versions up to 2.57.0 are impacted. Users are advised to update to version 2.58.0, which corrects the issue by generating a unique secret. Active two-factor authentication (2FA) can also prevent unauthorized access. Although a proof-of-concept exists, no real-world exploitation has been reported.
CVE-2026-52824: Default Docker Secret in Kimai Enables Account Takeover of Super Admin Accounts
CyberSIXT Evidence Panel
Article by CyberSIXT