Skip to content
Memcached SASL Vulnerability Allows Username Enumeration Attacks

Memcached SASL Vulnerability Allows Username Enumeration Attacks

First seen 26 May 2026, 12:07 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 27, 2026 at 12:05 UTC
  • CVE-2026-47783 allows username enumeration via a timing side-channel attack.
  • Affected versions of Memcached are those prior to 1.6.42.
  • The vulnerability was patched in the recent Memcached update released on May 20, 2026.

A timing side-channel vulnerability in Memcached's SASL authentication mechanism, tracked as CVE-2026-47783, has been disclosed. This flaw affects versions prior to 1.6.42 and enables attackers to enumerate valid usernames. The vulnerability was confirmed by researchers and poses a significant risk to systems using Memcached for password database authentication. The flaw was addressed in the latest release, which includes multiple critical bug fixes. Security professionals are urged to update their systems to mitigate potential exploitation. The vulnerability was published on May 20, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 106d ago How this analysis works

Timeline

2026-05-20
CVE-2026-47783 published
A timing side-channel vulnerability in Memcached's SASL authentication was disclosed, affecting versions before 1.6.42.
Gbhackers
2026-05-26
Memcached version 1.6.42 released
A security-focused update was released to address CVE-2026-47783 and other critical bugs.
Cybersecuritynews

More articles in this cluster (8)

Following this threat?

Track CVE-2026-47783 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed