Kimai A.I CyberSecurity Scoring
Kimai
Company Information
Website:https://www.kimai.org
Employees number:2
Number of followers:174
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:kimai.org
Kimai Risk Score (AI oriented)
Between 700 and 749
KimaiIT Services and IT Consulting
Updated:
20/07/2026
20/07/2026
747/1000
Moderate
Ba
Kimai Global Score (TPRM)
xxxx
KimaiIT Services and IT Consulting
Score locked

KimaiModerate
Current Score
747Ba (MODERATE)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
748
JULY 2026
747
JUNE 2026
749
Vulnerability
11 Jun 2026 • Kimai
Kimai: Kimai Docker Vulnerability Exposes Default APP_SECRET, Enabling Account Takeover
Critical Kimai Docker Vulnerability Exposes Deployments to Account Takeover (CVE-2026-52824)
747
CRITICAL-2
KIM1784528630
Critical Kimai Docker Vulnerability Exposes Deployments to Account Takeover (CVE-2026-52824)
A critical vulnerability in Kimai’s official Docker image, tracked as CVE-2026-52824 (GHSA-jr9p-4h4j-6c58), has been disclosed, exposing installations to account takeover risks due to a publicly known default cryptographic secret. The flaw affects Kimai versions 2.57.0 and earlier and was patched in version 2.58.0, released following a report by security researcher AzureADTrent and publication by maintainer Kevin Papst on June 11.
### Root Cause & Exploitation Risks
The vulnerability stems from an insecure default configuration in Kimai’s Docker image, where the environment variable `APP_SECRET=change_this_to_something_unique` intended to be replaced during deployment was never validated or enforced. This secret serves as the `kernel.secret` in Symfony, a cryptographic key used to sign security artifacts like remember-me cookies, CSRF tokens, password-reset URLs, and LoginLink signatures.
If left unchanged, attackers could exploit the predictable secret to forge authentication tokens and impersonate users, including super_admin accounts. Successful exploitation requires:
- Knowledge of the target username,
- The account ID (often sequential, e.g., `11` for the first admin),
- A lack of two-factor authentication (2FA) on the target account.
User IDs may be exposed in URLs or API responses, further simplifying attacks.
### Impact & Mitigation
The issue, classified as CWE-1188 ("Initialization of a Resource with an Insecure Default"), underscores a broader problem in container security: hardcoded secrets in production images without enforcement of secure initialization.
Kimai’s 2.58.0 patch addresses the flaw by:
- Automatically generating a random `APP_SECRET` (`bin2hex(random_bytes(32))`) if none is provided,
- Storing the secret in `/opt/kimai/var/data/.appsecret` and writing it to `/opt/kimai/.env.local`,
- Removing the insecure default from the Dockerfile and updating documentation to emphasize unique, deployment-specific secrets.
Additionally, Kimai increased entropy in LoginLink values (GHSA-m492-gv72-xvxj) to prevent attackers from generating valid links using the default secret though this is not a substitute for patching.
### Recommended Actions
Affected organizations must:
- Upgrade to Kimai 2.58.0 or later,
- Explicitly set a strong, unique `APP_SECRET`,
- Rotate secrets on potentially compromised instances,
- Invalidate active sessions, review admin accounts, and enable 2FA,
- Restrict public access to Kimai instances where unnecessary.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MAY 2026
749
APRIL 2026
749
MARCH 2026
749
FEBRUARY 2026
749
JANUARY 2026
749
DECEMBER 2025
749
NOVEMBER 2025
749
OCTOBER 2025
749
SEPTEMBER 2025
749
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Kimai ??
What was Kimai's A.I Rankiteo Cyber Score in July 2026 ??
What was Kimai's A.I Rankiteo Cyber Score in June 2026 ??
What was Kimai's A.I Rankiteo Cyber Score in May 2026 ??
What was Kimai's A.I Rankiteo Cyber Score in April 2026 ??
What was Kimai's A.I Rankiteo Cyber Score in March 2026 ??
What was Kimai's A.I Rankiteo Cyber Score in February 2026 ??
What was Kimai's A.I Rankiteo Cyber Score in January 2026 ??
What was Kimai's A.I Rankiteo Cyber Score in December 2025 ??
What was Kimai's A.I Rankiteo Cyber Score in November 2025 ??
What was Kimai's A.I Rankiteo Cyber Score in October 2025 ??
What was Kimai's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Kimai's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Kimai ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Kimai's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?