← back
CVE-2026-8794mediumCWE-208

PaperCut NG/MF: User enumeration via timing attack

33Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 6.9epss 0.4%
from disclosure to weapon12 days
Published on NVDAug 3
1st PoC+12d
exploitation probability
0.4%top 68% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is supplied, creating a measurable timing oracle that reveals account existence.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.