logo

Memcached SASL Flaw Exposes Usernames to Enumeration Attacks

ID: 0aa78e25-7d60-508e-9527-35963d46a1e6

STIX ID: report--0aa78e25-7d60-508e-9527-35963d46a1e6

Feed Name: GBHackers

Threat Score
55/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Divya

...
...

A timing side-channel vulnerability in Memcached's SASL username validation (CVE-2026-47783) affects versions prior to 1.6.42 and can be abused to remotely enumerate valid usernames by measuring authentication response times. The issue is patched in Memcached 1.6.42, which normalizes processing time during username validation; administrators are strongly advised to upgrade because enumerated usernames can be used with brute-force or credential-stuffing to gain unauthorized access, particularly when Memcached instances are exposed to untrusted networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.