Timing Discrepancy Vulnerability in PaperCut NG/MF from PaperCut
CVE-2026-8794

6.9MEDIUM

Key Information:

Vendor

Papercut

Vendor
CVE Published:
3 August 2026

What is CVE-2026-8794?

PaperCut NG/MF features an undisclosed flaw within its authentication mechanism that allows unauthenticated remote attackers to exploit timing discrepancies. By analyzing the response times of login attempts, attackers can conduct username enumeration. The system engages in password hash comparisons solely when a valid account is issued, effectively creating a timing oracle that signals the existence of an account based on the response time discrepancies. This weakness poses a risk to the confidentiality of account information, allowing potential attackers to formulate targeted follow-up attacks based on successful username discovery.

Affected Version(s)

PaperCut NG/MF 0 < 26.0.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vivien Lebas
.