Description
Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces nor rejects that value before Symfony uses it as kernel.secret. An unauthenticated attacker who reaches a deployment that did not override APP_SECRET, knows a username, correctly guesses the account ID associated with that username, and targets an account without active two-factor authentication can forge HMAC-protected authentication artifacts, including KIMAI_REMEMBER cookies and login links, to access the account without its password. The updated entrypoint generates and persists a random secret when no safe operator-provided value exists. This issue is fixed in version 2.58.0.
Published: 2026-09-15
Score: 9.1 Critical
EPSS: 1.3% Low
KEV: No
Impact: Account takeover through cookie forgery
Action: Immediate Patch
AI Analysis

Impact

This vulnerability originates in the official Kimai Docker image for versions before 2.58.0, which hard‑codes the APP_SECRET to "change_this_to_something_unique" in the Dockerfile. The Docker image's entrypoint does not replace or reject this default value before Symfony uses it as kernel.secret. Because the kernel.secret is used as the key for HMAC‑protected authentication artifacts, an attacker who can reach an unpatched deployment, knows a victim's username, and can correctly guess the associated account ID can forge KIMAI_REMEMBER cookies or login links if two‑factor authentication is disabled. The attacker can therefore authenticate as the target without the password, enabling full account takeover. The entrypoint has been updated in Kimai 2.58.0 to generate and persist a random secret when no operator‑provided value is present, fixing the issue. The weakness is identified as CWE‑1188.

Affected Systems

The affected environment is the official Kimai Docker image provided by the kimai:kimai project. Versions of the image prior to Kimai 2.58.0 contain the default, hard‑coded APP_SECRET value. Updating to Kimai 2.58.0 or later replaces the entrypoint logic with generation of a random secret when one is not supplied by a secure operator, thereby removing the vulnerability.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity. The EPSS score of 2% indicates a moderate likelihood that the vulnerability will be exploited. It is not KEV catalog. An attacker with unauthenticated network access can, with knowledge of a target username and account ID and the absence of second‑factor authentication, forge authentication artifacts through HMAC manipulation. Forged artifacts allow the attacker to impersonate the target user with full privileges without the original password.

Generated by OpenCVE AI on September 20, 2026 at 18:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Kimai deployment to version 2.58.0 or newer to benefit from the updated entrypoint that generates a random secret if none is provided.
  • If an upgrade is not immediately possible, override the default APP_SECRET by setting a strong, unique secret via an environment variable in the Docker configuration before launching the container.
  • Enable two‑factor authentication for all user accounts to provide an additional layer of protection against cookie forgery attacks.

Generated by OpenCVE AI on September 20, 2026 at 18:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jr9p-4h4j-6c58 Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover
History

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Kimai
Kimai kimai
Vendors & Products Kimai
Kimai kimai

Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces nor rejects that value before Symfony uses it as kernel.secret. An unauthenticated attacker who reaches a deployment that did not override APP_SECRET, knows a username, correctly guesses the account ID associated with that username, and targets an account without active two-factor authentication can forge HMAC-protected authentication artifacts, including KIMAI_REMEMBER cookies and login links, to access the account without its password. The updated entrypoint generates and persists a random secret when no safe operator-provided value exists. This issue is fixed in version 2.58.0.
Title Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover
Weaknesses CWE-1188
References
Metrics cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T17:33:01.273Z

Reserved: 2026-06-08T18:11:06.661Z

Link: CVE-2026-52824

cve-icon Vulnrichment

Updated: 2026-09-16T17:32:57.883Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:09.543

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-52824

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:15:17Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default