CVE-2026-80199 UNKNOWN

CVE-2026-80199

Published: 2026-08-26

Description

Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response time differences when the password hasher runs only for existing users, enabling username enumeration with no login throttling protection.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…