Kimai <= 2.57.0 Default APP_SECRET Authentication Bypass Vulnerability (CVE-2026-52824)
Introduction Kimai, an open-source time tracking and project management platform, is widely used by organizations and freelancers worldwide to manage sensitive operational, financial, and client data. However, a critical security flaw identified as CVE-2026-52824, affecting version 2.57.0 and earlier, highlights the severe consequences of insecure default configurations in production environments. When cryptographic secrets remain unchanged