{"id":"CVE-2026-8793","title":"PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component","summary":"PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks …","severity":"none","cwe":["CWE-307"],"published":"2026-08-03","updated":"2026-09-09","sourceUpdated":"2026-09-09T16:03:59.890","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-8793","references":[{"url":"https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-3-aug-2026/","label":"eb41dac7-0af8-4f84-9f6d-0272772514f4"}],"tags":["nvd","exploit-available"],"epss":0.0039,"epssPercentile":0.33036,"exploits":{"github":1,"githubRepos":["https://github.com/H4zaz/CVE-2026-8793"],"checkedAt":"2026-09-24T07:53:22.847Z"},"exploitAvailable":true,"ingestedAt":"2026-09-09T16:14:05.511Z","slug":"CVE-2026-8793","body":"## Overview\n\nPaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks without triggering account lockout or rate-limiting mechanisms in some configurations.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":15,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}