PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is supplied, creating a measurable timing oracle that reveals account existence.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Aug 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is supplied, creating a measurable timing oracle that reveals account existence. | |
| Title | PaperCut NG/MF: User enumeration via timing attack | |
| Weaknesses | CWE-208 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: PaperCut
Published:
Updated: 2026-08-03T07:02:42.064Z
Reserved: 2026-05-17T23:10:23.139Z
Link: CVE-2026-8794
No data.
No data.
No data.
OpenCVE Enrichment
No data.