Known CVE
Kimai <= 2.57.0 - Default APP_SECRET Authentication Bypass
Kimai Docker images <= 2.57.0 ship with a hardcoded APP_SECRET of "change_this_to_something_unique". This default secret is used by Symfony's SignatureHasher to HMAC-sign login links and remember-me cookies. An unauthenticated attacker who knows this default secret can forge valid authentication tokens and hijack any user account, including the super-admin.
CVE-2026-52824
Critical2026CVSS 9.1CWE-1188
cve2026 · kimai · default-secret · auth-bypass · account-takeover
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website