PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is supplied, creating a measurable timing oracle that reveals account existence.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Papercut
Papercut papercut Mf |
|
| Vendors & Products |
Papercut
Papercut papercut Mf |
Mon, 03 Aug 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is supplied, creating a measurable timing oracle that reveals account existence. | |
| Title | PaperCut NG/MF: User enumeration via timing attack | |
| Weaknesses | CWE-208 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: PaperCut
Published:
Updated: 2026-08-03T14:30:36.904Z
Reserved: 2026-05-17T23:10:23.139Z
Link: CVE-2026-8794
Updated: 2026-08-03T14:30:12.556Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-03T15:00:15Z