CVE-2026-8794: PaperCut NG/MF: User enumeration via timing attack
PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is supplied, creating a measurable timing oracle that reveals account existence.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8794?
The severity of CVE-2026-8794 is medium, with a CVSS score of 6.9.
How do I fix CVE-2026-8794?
To fix CVE-2026-8794, update your PaperCut NG/MF software to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-8794?
CVE-2026-8794 is a user enumeration vulnerability that can be exploited via a timing attack.
Who can exploit CVE-2026-8794?
An unauthenticated remote attacker can exploit CVE-2026-8794 to perform username enumeration.
What is the impact of CVE-2026-8794?
The impact of CVE-2026-8794 allows an attacker to gain information about valid usernames by measuring response times during login attempts.