-
Help Center home
-
Product manuals
-
Release notes
-
System requirements
Contents
PaperCut NG/MF Security Bulletin (3 Aug 2026)
Last updated August 3, 2026
Contents
Summary
At PaperCut, we are consistently working on improving the security posture of our products. This ongoing commitment involves regular internal audits, proactive “pattern hunting” in our codebase, and collaboration with external security researchers. This process is designed to identify and remediate potential issues before they can be exploited.
PaperCut prioritizes the safety of our customers through a responsible disclosure policy. As part of this approach, you may observe specific CVE identifiers appearing in our product release notes before a formal security bulletin or a CVE database entry is fully published. This “fix-first” strategy allows us to provide immediate protection while delaying the publication of technical details that could be used to develop exploits. Full documentation is published only when we are confident that disclosure no longer poses an immediate risk to our customer base.
This bulletin addresses the following security vulnerabilities affecting PaperCut NG/MF:
- CVE-2026-8793: Insufficient brute-force protection
- CVE-2026-8794: User enumeration via timing attack
Recommendation: PaperCut recommends that PaperCut NG/MF customers upgrade to version 26.0.3 (or later).
Security issues addressed
| CVE | Notes | CVSS rating and vector |
| CVE-2026-8793 Insufficient brute-force protection | PaperCut NG/MF does not restrict excessive authentication attempts in its login component. An unauthenticated remote attacker could exploit this to perform brute-force or credential‑stuffing attacks without triggering account lockout or rate‑limiting in some configurations. Vulnerability Type: Missing brute-force protection (CWE-307) Impact: There is a potential to brute-force a password for an existing PaperCut NG/MF user. Fixed in: PaperCut NG/MF versions 26.0.3 and later. | 6.9 (MEDIUM)
|
| CVE-2026-8794 User enumeration via timing attack | PaperCut NG/MF has a timing discrepancy in its authentication component. An unauthenticated remote attacker can enumerate usernames by measuring response times during login attempts. The application performs a password hash comparison only for valid accounts, creating a timing oracle that discloses account existence. Vulnerability Type: Observable Timing Discrepancy (CWE-208) Impact: It is possible to detect whether a user account exists in the system with high probability. Fixed in: PaperCut NG/MF versions 26.0.3 and later. | 6.9 (MEDIUM)
|
Who is impacted
You are likely impacted if you are running PaperCut NG/MF versions prior to 26.0.3.
Steps to resolve
PaperCut recommends that all customers upgrade to the latest version of PaperCut NG or MF inline with their upgrade cycle.
- Upgrade PaperCut NG/MF: Install the latest build from the PaperCut website.
FAQs
No. These security improvements require code-level changes found only in the latest releases. To resolve this issue, customers must ensure their environment is running PaperCut NG/MF version 26.0.3 or later.
No. The vulnerabilities were reported to PaperCut by security researchers under the responsible disclosure policy. PaperCut does not possess any knowledge of the vulnerabilities being exploited and the fixes are not a response to any known exploits.
Security notifications
To stay informed about high impact security updates please subscribe to our Security notifications sign-up form.
Updates
Date | Update/action |
03 August, 2026 (AEST) | Published the initial Security Bulletin. |
03 August 2026 (AEST) | Updated CVSS score from 5.3 to 6.9 (still Medium). Removed the environmental MAV:A modifier. |
Category: Security Bulletins
Subcategory: Security and Privacy
Comments