Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Kimai

Kimai Vendor Cyber Rating & Cyber Score

kimai.org

Time-tracking made in Austria. Cloud hosted in Germany. Full GDPR compliance. Powered by open-source software.


Kimai A.I CyberSecurity Scoring

Kimai
Company Information
Website:https://www.kimai.org
Employees number:2
Number of followers:174
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:kimai.org
Kimai Risk Score (AI oriented)
Between 700 and 749
logo
KimaiIT Services and IT Consulting
Updated:
20/07/2026
747/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Kimai Global Score (TPRM)
xxxx
logo
KimaiIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Kimai
KimaiModerate
Current Score
747Ba (MODERATE)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
748Before Incident
JULY 2026
747Before Incident
JUNE 2026
749Before Incident
Vulnerability
11 Jun 2026Kimai
Kimai: Kimai Docker Vulnerability Exposes Default APP_SECRET, Enabling Account Takeover

Critical Kimai Docker Vulnerability Exposes Deployments to Account Takeover (CVE-2026-52824)

747After Incident
CRITICAL-2
KIM1784528630
Critical Kimai Docker Vulnerability Exposes Deployments to Account Takeover (CVE-2026-52824) A critical vulnerability in Kimai’s official Docker image, tracked as CVE-2026-52824 (GHSA-jr9p-4h4j-6c58), has been disclosed, exposing installations to account takeover risks due to a publicly known default cryptographic secret. The flaw affects Kimai versions 2.57.0 and earlier and was patched in version 2.58.0, released following a report by security researcher AzureADTrent and publication by maintainer Kevin Papst on June 11. ### Root Cause & Exploitation Risks The vulnerability stems from an insecure default configuration in Kimai’s Docker image, where the environment variable `APP_SECRET=change_this_to_something_unique` intended to be replaced during deployment was never validated or enforced. This secret serves as the `kernel.secret` in Symfony, a cryptographic key used to sign security artifacts like remember-me cookies, CSRF tokens, password-reset URLs, and LoginLink signatures. If left unchanged, attackers could exploit the predictable secret to forge authentication tokens and impersonate users, including super_admin accounts. Successful exploitation requires: - Knowledge of the target username, - The account ID (often sequential, e.g., `11` for the first admin), - A lack of two-factor authentication (2FA) on the target account. User IDs may be exposed in URLs or API responses, further simplifying attacks. ### Impact & Mitigation The issue, classified as CWE-1188 ("Initialization of a Resource with an Insecure Default"), underscores a broader problem in container security: hardcoded secrets in production images without enforcement of secure initialization. Kimai’s 2.58.0 patch addresses the flaw by: - Automatically generating a random `APP_SECRET` (`bin2hex(random_bytes(32))`) if none is provided, - Storing the secret in `/opt/kimai/var/data/.appsecret` and writing it to `/opt/kimai/.env.local`, - Removing the insecure default from the Dockerfile and updating documentation to emphasize unique, deployment-specific secrets. Additionally, Kimai increased entropy in LoginLink values (GHSA-m492-gv72-xvxj) to prevent attackers from generating valid links using the default secret though this is not a substitute for patching. ### Recommended Actions Affected organizations must: - Upgrade to Kimai 2.58.0 or later, - Explicitly set a strong, unique `APP_SECRET`, - Rotate secrets on potentially compromised instances, - Invalidate active sessions, review admin accounts, and enable 2FA, - Restrict public access to Kimai instances where unnecessary.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Authentication tokens, CSRF tokens, password-reset URLs, LoginLink signaturesSystems Affected: Kimai Docker deployments (versions 2.57.0 and earlier)Operational Impact: Account takeover, unauthorized access to admin accountsBrand Reputation Impact: Potential reputational damage due to insecure default configurationsIdentity Theft Risk: High (if PII or admin accounts are compromised)
DATA BREACH
Type Of Data Compromised: Authentication tokens, CSRF tokens, password-reset URLs, LoginLink signaturesSensitivity Of Data: High (authentication artifacts, admin account access)Personally Identifiable Information: Potential (if admin accounts contain PII)
MAY 2026
749Before Incident
APRIL 2026
749Before Incident
MARCH 2026
749Before Incident
FEBRUARY 2026
749Before Incident
JANUARY 2026
749Before Incident
DECEMBER 2025
749Before Incident
NOVEMBER 2025
749Before Incident
OCTOBER 2025
749Before Incident
SEPTEMBER 2025
749Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Kimai ?
?
What was Kimai's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Kimai's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Kimai's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Kimai's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Kimai's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Kimai's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Kimai's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Kimai's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Kimai's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Kimai's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Kimai's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Kimai's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Kimai ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Kimai's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?