CVE-2026-8793: CWE-307 Improper restriction of excessive authentication attempts in PaperCut PaperCut NG/MF
CVE-2026-8793 is a vulnerability in PaperCut NG/MF where the software does not properly restrict excessive authentication attempts. This allows unauthenticated remote attackers to perform unlimited brute-force or credential-stuffing attacks without triggering account lockout or rate-limiting in some configurations. The vulnerability has a medium severity rating with a CVSS score of 6.9. No patch or official remediation guidance is currently available, and no known exploits are reported in the wild.
AI Analysis
Technical Summary
PaperCut NG/MF contains an improper restriction of excessive authentication attempts (CWE-307) vulnerability in its login component. This flaw permits unauthenticated remote attackers to conduct unrestricted brute-force or credential-stuffing attacks because the system fails to enforce account lockout or rate-limiting mechanisms under certain configurations. The vulnerability is identified as CVE-2026-8793 with a CVSS 4.0 base score of 6.9, indicating a medium level of risk. No vendor advisory or patch information is currently provided, and the affected versions are not explicitly stated.
Potential Impact
An attacker can perform unlimited authentication attempts remotely without triggering lockout or rate-limiting protections, increasing the risk of successful brute-force or credential-stuffing attacks. This could lead to unauthorized access if valid credentials are compromised. However, no known active exploitation has been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, organizations should consider implementing external protections such as network-level rate limiting or multi-factor authentication to mitigate brute-force risks.
CVE-2026-8793: CWE-307 Improper restriction of excessive authentication attempts in PaperCut PaperCut NG/MF
Description
CVE-2026-8793 is a vulnerability in PaperCut NG/MF where the software does not properly restrict excessive authentication attempts. This allows unauthenticated remote attackers to perform unlimited brute-force or credential-stuffing attacks without triggering account lockout or rate-limiting in some configurations. The vulnerability has a medium severity rating with a CVSS score of 6.9. No patch or official remediation guidance is currently available, and no known exploits are reported in the wild.
CVSS v4.0
Score 6.9medium
Affected software
PaperCut
PaperCut NG/MF
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
PaperCut NG/MF contains an improper restriction of excessive authentication attempts (CWE-307) vulnerability in its login component. This flaw permits unauthenticated remote attackers to conduct unrestricted brute-force or credential-stuffing attacks because the system fails to enforce account lockout or rate-limiting mechanisms under certain configurations. The vulnerability is identified as CVE-2026-8793 with a CVSS 4.0 base score of 6.9, indicating a medium level of risk. No vendor advisory or patch information is currently provided, and the affected versions are not explicitly stated.
Potential Impact
An attacker can perform unlimited authentication attempts remotely without triggering lockout or rate-limiting protections, increasing the risk of successful brute-force or credential-stuffing attacks. This could lead to unauthorized access if valid credentials are compromised. However, no known active exploitation has been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, organizations should consider implementing external protections such as network-level rate limiting or multi-factor authentication to mitigate brute-force risks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- PaperCut
- Date Reserved
- 2026-05-17T23:10:16.657Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a704b63bf32cb7a3433eb52
Added to database: 08/03/2026, 08:03:47 UTC
Last enriched: 08/10/2026, 15:20:30 UTC
Last updated: 09/17/2026, 22:01:39 UTC
Views: 83
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.