Back

CRITICAL

Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover

Published Sep 15, 2026

Description

Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces nor rejects that value before Symfony uses it as kernel.secret. An unauthenticated attacker who reaches a deployment that did not override APP_SECRET, knows a username, correctly guesses the account ID associated with that username, and targets an account without active two-factor authentication can forge HMAC-protected authentication artifacts, including KIMAI_REMEMBER cookies and login links, to access the account without its password. The updated entrypoint generates and persists a random secret when no safe operator-provided value exists. This issue is fixed in version 2.58.0.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Sep 15, 2026
Updated Sep 16, 2026
Reserved Jun 8, 2026

CISA Vulnrichment

Updated Sep 16, 2026

NVD

Status Received
Modified Sep 16, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Sep 15, 2026
Updated Sep 16, 2026