Timing Discrepancy Vulnerability in PaperCut NG/MF from PaperCut
CVE-2026-8794
6.9MEDIUM
What is CVE-2026-8794?
PaperCut NG/MF features an undisclosed flaw within its authentication mechanism that allows unauthenticated remote attackers to exploit timing discrepancies. By analyzing the response times of login attempts, attackers can conduct username enumeration. The system engages in password hash comparisons solely when a valid account is issued, effectively creating a timing oracle that signals the existence of an account based on the response time discrepancies. This weakness poses a risk to the confidentiality of account information, allowing potential attackers to formulate targeted follow-up attacks based on successful username discovery.
Affected Version(s)
PaperCut NG/MF 0 < 26.0.3
