CVE-2026-8794None▾ TwilightPoC availablePaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 2.8 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
1 GitHub repo (last check)
PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is supplied, creating a measurable timing oracle that reveals account existence.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-70658High· 7.4Pay is a payments engine for Ruby on Rails 6.0 and higher
CVE-2026-77582Medium· 6.9Tinyauth is an authentication and authorization server
CVE-2026-47783High· 8.1In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
CVE-2026-72701Low· 3.7Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection
GHSA-px9v-979x-qmh9Medium· 3.7Duplicate Advisory: Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection
CVE-2026-81159Low· 3.7Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force