PT-2026-81912 · Kimai · Kimai

·

CVE-2026-80199

·

Published

2026-04-17

·

Updated

2026-08-26

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kimai versions prior to 2.54.0
Description A timing oracle issue exists in the TokenAuthenticator component. This allows unauthenticated attackers to perform username enumeration by analyzing response time differences, as the password hasher only executes for users that already exist in the system. This process is facilitated through the X-AUTH-USER header and is not mitigated by login throttling protections.
Recommendations Update to version 2.54.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80199
GHSA-JRC6-FMHW-FPQ2

Affected Products

Kimai