CVE-2026-8793: PaperCut NG/MF: Insufficient brute-force protection
PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks without triggering account lockout or rate-limiting mechanisms in some configurations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8793?
CVE-2026-8793 has a medium severity rating of 6.9 according to the CVSS scoring system.
How do I fix CVE-2026-8793?
To fix CVE-2026-8793, update to the latest version of PaperCut NG/MF that includes patches for this vulnerability.
What type of attack does CVE-2026-8793 allow?
CVE-2026-8793 allows attackers to perform unrestricted brute-force or credential-stuffing attacks on the login component.
Who is affected by CVE-2026-8793?
CVE-2026-8793 affects users of PaperCut NG/MF who utilize its authentication login feature.
Can CVE-2026-8793 be exploited remotely?
Yes, CVE-2026-8793 can be exploited remotely by unauthenticated attackers.