MEDIUM 6.3 NVD
CVE-2026-80199
Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-U
Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response time differences when the password hasher runs only for existing users, enabling username enumeration with no login throttling protection.
References
- https://github.com/kimai/kimai/security/advisories/GHSA-jrc6-fmhw-fpq2
- https://www.vulncheck.com/advisories/kimai-before-2.54.0-username-enumeration-via-timing-o
This medium severity vulnerability with a CVSS score of 6.3 was published on 2026-08-26 via NVD.
vulnfeed aggregates 11364 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.