CVE-2026-80199: Kimai before 2.54.0 Username Enumeration via Timing Oracle

Published Aug 25, 2026
·
Updated

Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response time differences when the password hasher runs only for existing users, enabling username enumeration with no login throttling protection.

Affected Software

1 affected component
Kimai Kimai<2.54.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Kimai to a version that resolves this vulnerability.

    Fixed in 2.54.0
  2. Configuration

    Upgrade Kimai to 2.54.0 to remediate the timing oracle in TokenAuthenticator that enables username enumeration via the X-AUTH-USER header.

    Kimai TokenAuthenticator X-AUTH-USER header handling = Apply fix in Kimai before 2.54.0 to prevent timing-based username enumeration via X-AUTH-USER

Event History

Aug 25, 2026
CVE Published
via MITRE·11:19 PM
Data Sourced
via MITRE·11:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue, and what access is required?

Any unauthenticated remote attacker can attempt exploitation by sending requests with the X-AUTH-USER header and measuring response-time differences. No account, privileges, or user interaction are required.

2

What can an attacker gain from exploiting the timing oracle?

The issue allows enumeration of valid usernames. The provided information does not indicate direct password disclosure, authentication bypass, data modification, or denial-of-service impact.

3

Why are response times different for valid and invalid usernames?

For existing users, the password hasher runs, creating a measurable timing difference. This behavior occurs in TokenAuthenticator and can reveal whether a supplied username exists.

4

Does login throttling mitigate this attack?

No. The vulnerability description states that there is no login throttling protection for this enumeration method.

5

Which versions need remediation?

Kimai versions before 2.54.0 are affected. Updating to version 2.54.0 or later addresses the affected version range described.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203