PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is supplied, creating a measurable timing oracle that reveals account existence.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-03 08:17
Updated : 2026-09-09 16:03
NVD link : CVE-2026-8794
Mitre link : CVE-2026-8794
CVE.ORG link : CVE-2026-8794
JSON object : View
Products Affected
No product.
CWE
CWE-208
Observable Timing Discrepancy
