CVE-2026-8793
PaperCut NG/MF: Insufficient brute-force protection
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks without triggering account lockout or rate-limiting mechanisms in some configurations.
| CWE | CWE-307 |
| Vendor | papercut |
| Product | papercut ng/mf |
| Published | Aug 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for papercut papercut ng/mf
Be the first to know when new unknown vulnerabilities affecting papercut papercut ng/mf are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
PaperCut / PaperCut NG/MF
0 < 26.0.3
References
Credits
๐ Vivien Lebas