CVE-2026-80199

Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response time differences when the password hasher runs only for existing users, enabling username enumeration with no login throttling protection.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-26 05:18

Updated : 2026-08-31 20:52


NVD link : CVE-2026-80199

Mitre link : CVE-2026-80199

CVE.ORG link : CVE-2026-80199


JSON object : View

Products Affected

No product.

CWE
CWE-208

Observable Timing Discrepancy