Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response time differences when the password hasher runs only for existing users, enabling username enumeration with no login throttling protection. | |
| Title | Kimai before 2.54.0 Username Enumeration via Timing Oracle | |
| First Time appeared |
Kimai
Kimai kimai |
|
| Weaknesses | CWE-208 | |
| CPEs | cpe:2.3:a:kimai:kimai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kimai
Kimai kimai |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T23:19:05.166Z
Reserved: 2026-08-25T23:14:37.730Z
Link: CVE-2026-80199
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-26T01:45:03Z
-
CWE-208
Observable Timing Discrepancy