Executive brief
Kimai is a time-tracking and billing application used by organizations to manage employee work hours. The authentication system leaks information about whether a username exists through measurable differences in response time, allowing attackers to discover valid user accounts without credentials. This weakens security by enabling attackers to build a list of real users to target with password attacks.
Technical details
A timing oracle vulnerability exists in TokenAuthenticator.php where the password hasher (argon2id) is only invoked when a user is found via loadUserByIdentifier(). When a non-existent username is queried, the response returns approximately 25 ms faster than for a valid username, despite returning identical HTTP 403 responses with the same error message. The legacy X-AUTH-USER and X-AUTH-TOKEN headers accept unauthenticated requests to the /api/* endpoints with no login throttling, allowing unbounded probing. An attacker can enumerate valid usernames by measuring response times from the /api/users/me endpoint. The vulnerability is fixed in version 2.54.0 by running the password hasher against a fixed dummy hash even when the user is not found, ensuring constant-time responses regardless of user existence.
Affected products
- Kimai Kimai before 2.54.0
Timeline
- 2026-04-16: disclosed
- 2026-08-25: advisory
- 2026-04-16: patched: patched in version 2.54.0