Junglewise Threat Intelligence

CVE-2026-80199: Kimai TokenAuthenticator username enumeration via timing oracle

CVE-2026-80199 · Severity: low · CVSS 3.7 · Published 2026-08-26

Technologies: kimai/kimai (Packagist), Kimai. Vendors: Packagist, Kimai.

Executive brief

Kimai is a time-tracking and billing application used by organizations to manage employee work hours. The authentication system leaks information about whether a username exists through measurable differences in response time, allowing attackers to discover valid user accounts without credentials. This weakens security by enabling attackers to build a list of real users to target with password attacks.

Technical details

A timing oracle vulnerability exists in TokenAuthenticator.php where the password hasher (argon2id) is only invoked when a user is found via loadUserByIdentifier(). When a non-existent username is queried, the response returns approximately 25 ms faster than for a valid username, despite returning identical HTTP 403 responses with the same error message. The legacy X-AUTH-USER and X-AUTH-TOKEN headers accept unauthenticated requests to the /api/* endpoints with no login throttling, allowing unbounded probing. An attacker can enumerate valid usernames by measuring response times from the /api/users/me endpoint. The vulnerability is fixed in version 2.54.0 by running the password hasher against a fixed dummy hash even when the user is not found, ensuring constant-time responses regardless of user existence.

Affected products

  • Kimai Kimai before 2.54.0

Timeline

  • 2026-04-16: disclosed
  • 2026-08-25: advisory
  • 2026-04-16: patched: patched in version 2.54.0

References

Related threats