A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.
{
"cwe_ids": [
"CWE-286"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-30T23:23:52Z",
"nvd_published_at": "2024-04-10T15:16:05Z",
"severity": "MODERATE"
}