Sploitus

CVE-2026-80199

No indexed exploits for CVE-2026-80199 yet

Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response time differences when the password hasher runs only for existing users, enabling username enumeration with no login throttling protection.

Affected products
Kimai
Fix
Available
CVSS 4.0
6.3 MEDIUM
CVSS 3.1
3.7 LOW
EPSS
0.2% (16th percentile)
Weakness
CWE-208
NVD status
Deferred
Published
2026-08-25
CVE-2026-80199 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-80199 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-80199 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.