CVE-2026-52824 is an authentication-bypass vulnerability in Kimai versions before 2.58.0. The official Docker image configured Symfony's kernel secret from a publicly known default APP_SECRET value, while container initialization neither rejected nor replaced that unsafe value. Deployments that retained the default secret use a predictable key for HMAC-protected security artifacts. An unauthenticated remote attacker can use the known secret to forge authentication artifacts, including remember-me cookies and login links, enabling impersonation of eligible accounts without knowing their passwords.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This 11-file Python repository is an operational exploitation toolkit for the claimed Kimai CVE-2026-52824 default-secret flaw. The principal exploit, exploit.py, constructs a Symfony KIMAI_REMEMBER cookie for a supplied username by using the hard-coded APP_SECRET and a constant empty signature-properties hash, then attempts to access the target with that cookie. It supports custom secrets, expiry, TLS-verification disabling, output of a cookie, and cookie-only (--dump) operation. Supporting scripts scale target discovery and exploitation: batch_pwn.py concurrently tests supplied URLs with a forged cookie; probe_batch.py and deep_probe.py identify Kimai and infer vulnerable versions via root and version/metadata paths; quick_scan.py runs a multi-stage scan and invokes exploit.py to create cookies; and shodan-scanner.py searches Shodan using Kimai title/body/favicon signatures and can probe supplied host lists. Network requests in several scanner scripts disable TLS certificate validation. Results and vulnerable-target lists are written to local text/JSON files. requirements.txt declares requests and shodan. No Metasploit, Nuclei, or other exploit framework is used.
This repository is a Python-based exploit toolkit for Kimai CVE-2026-52824, an authentication bypass/account takeover issue caused by the default APP_SECRET value and predictable Symfony remember-me cookie signing in Kimai <= 2.57.0. The main exploit logic is in exploit.py, which forges a KIMAI_REMEMBER cookie for an arbitrary username by computing a constant fields hash from SHA256('') and an HMAC-SHA256 using the known secret "change_this_to_something_unique". Successful use yields authenticated access as the targeted user, commonly admin or super_admin. Repository structure: exploit.py is the single-target exploit; batch_pwn.py performs multithreaded exploitation against many URLs; deep_probe.py and probe_batch.py are version/vulnerability detection utilities; quick_scan.py chains discovery, probing, and cookie generation into a multi-stage workflow; shodan-scanner.py discovers Kimai instances via Shodan queries and optional HTTP probing. requirements.txt lists requests and shodan. README.md documents the vulnerability, usage, and workflow. Main capabilities observed: (1) forge valid remember-me cookies for arbitrary usernames, (2) attempt authenticated access to target Kimai instances over HTTP/HTTPS, (3) identify Kimai instances by checking page content and login indicators, (4) probe multiple version disclosure endpoints such as /api/ping, /version, /api/version, /composer.json, /CHANGELOG.md, and /public/build/manifest.json, (5) batch process host lists and save vulnerable/exploited results, and (6) enumerate potential targets using Shodan title/body/favicon searches. Notable implementation details: TLS verification is commonly disabled in the scanners/exploit helpers; batch_pwn.py precomputes one forged cookie and reuses it across hosts; quick_scan.py contains a hardcoded local working directory for invoking exploit.py; deep_probe.py includes a minor code quality issue (datetime imported only at runtime before main save path usage), but the repository overall clearly contains functioning exploit and scanning code rather than a README-only or fake project.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical authentication-bypass/account-takeover vulnerability in Kimai's official Docker image caused by a public default APP_SECRET. Affected deployments may permit unauthenticated attackers to forge signed authentication cookies or login links for accounts without active two-factor authentication, given knowledge of a username and a correctly guessed account ID.
A critical authentication bypass/account takeover vulnerability in Kimai’s official Docker image caused by an insecure default APP_SECRET value, allowing remote unauthenticated attackers to forge trusted security tokens and cookies.
A critical authentication/account takeover vulnerability in Kimai caused by a publicly known default APP_SECRET in the official Docker image, enabling forged signed cookies and account hijacking.
An authentication bypass vulnerability affecting Kimai versions 2.57.0 and earlier, apparently related to use of a default APP_SECRET.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.