CVE-2026-52824Critical· 9.1▾ AbyssalPoC availableKimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces nor rejects that …
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 50.1 · likelihood 0.4 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
1 GitHub repo · Nuclei ×1
Disclosed via NVD
0.4%
— → 9.1
Last analysed / modified upstream
0.4% → 2.1%
Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces nor rejects that value before Symfony uses it as kernel.secret. An unauthenticated attacker who reaches a deployment that did not override APP_SECRET, knows a username, correctly guesses the account ID associated with that username, and targets an account without active two-factor authentication can forge HMAC-protected authentication artifacts, including KIMAI_REMEMBER cookies and login links, to access the account without its password. The updated entrypoint generates and persists a random secret when no safe operator-provided value exists. This issue is fixed in version 2.58.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
kimai/kimai <= 2.57.0Patched in:
kimai/kimai 2.58.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-52828Medium· 5.3Kimai is an open-source time tracking application
CVE-2026-52822Medium· 5.3Kimai is an open-source time tracking application
CVE-2026-52823Medium· 5.3Kimai is an open-source time tracking application
CVE-2026-52825Medium· 5.3Kimai is an open-source time tracking application
CVE-2026-52819Medium· 6.3Kimai is an open-source time tracking application
CVE-2026-49865Medium· 5.3Kimai is an open-source time tracking application