CVE-2026-8794 Details
Description
PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is supplied, creating a measurable timing oracle that reveals account existence.
A vulnerability in the authentication component of PaperCut NG/MF creates a timing discrepancy that can be exploited by an unauthenticated remote attacker to perform username enumeration. This is possible by measuring response times during login attempts, as the system only compares password hashes for valid accounts. This behavior creates a timing oracle that reveals whether an account exists.
Users are advised to upgrade to PaperCut NG/MF version 26.0.3 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-3-aug-2026/ | PaperCut |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-208 | Observable Timing Discrepancy | PaperCut |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | New CVE Received | PaperCut |