Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response time differences when the password hasher runs only for existing users, enabling username enumeration with no login throttling protection.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-26 05:18
Updated : 2026-08-31 20:52
NVD link : CVE-2026-80199
Mitre link : CVE-2026-80199
CVE.ORG link : CVE-2026-80199
JSON object : View
Products Affected
No product.
CWE
CWE-208
Observable Timing Discrepancy
