Unrated severityNVD Advisory· Published Aug 25, 2026
Kimai before 2.54.0 Username Enumeration via Timing Oracle
CVE-2026-80199
Description
Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response time differences when the password hasher runs only for existing users, enabling username enumeration with no login throttling protection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/kimai/kimai/security/advisories/GHSA-jrc6-fmhw-fpq2mitrevendor-advisory
- www.vulncheck.com/advisories/kimai-before-2.54.0-username-enumeration-via-timing-oraclemitrethird-party-advisory
News mentions
0No linked articles in our index yet.