Skip to content

Known CVE

Kimai <= 2.57.0 - Default APP_SECRET Authentication Bypass

Kimai Docker images <= 2.57.0 ship with a hardcoded APP_SECRET of "change_this_to_something_unique". This default secret is used by Symfony's SignatureHasher to HMAC-sign login links and remember-me cookies. An unauthenticated attacker who knows this default secret can forge valid authentication tokens and hijack any user account, including the super-admin.

CVE-2026-52824

Critical2026CVSS 9.1CWE-1188

cve2026 · kimai · default-secret · auth-bypass · account-takeover

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website