
Critical Kimai Docker Flaw Lets Hackers Forge Cookies and Hijack Admin Accounts
A critical vulnerability in the official Kimai Docker image has been disclosed, allowing unauthenticated attackers to forge authentication tokens and take over any user account, including super_admin, on affected deployments. Tracked as CVE-2026-52824, the flaw stems from a hardcoded default secret shipped in Kimai’s containerized deployments. The official Kimai Docker image sets APP_SECRET=change_this_to_something_unique as a […]
The post Critical Kimai Docker Flaw Lets Hackers Forge Cookies and Hijack Admin Accounts appeared first on Cyber Security News.