cvedb.io
CVE-2026-8794
UNKNOWN · CVSS n/a
EPSS exploitation probability: 0%
Published 2026-08-03T08:17:21.273 · Last modified 2026-08-03T08:17:21.273

Summary

PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is supplied, creating a measurable timing oracle that reveals account existence.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.