CVE-2026-8793: PaperCut Ng/mf

Medium severity, CVSS 6.9. EPSS: 0.7% chance of exploitation in the next 30 days.

PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks without triggering account lockout or rate-limiting mechanisms in some configurations.

Affected products

  • PaperCut PaperCut Ng/mf: before 26.0.3 (fixed in 26.0.3)

Published 2026-08-03. Last modified 2026-09-09.