CVE-2026-8793

Summary

PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks without triggering account lockout or rate-limiting mechanisms in some configurations.

Affected Software

VendorProductVersion RangeStatus
PaperCutPaperCut NG/MF0 < 26.0.3affected

Weaknesses

  • CWE-307: CWE-307 Improper restriction of excessive authentication attempts

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References