Memcached SASL Vulnerability Allows Username Enumeration Attacks

Memcached SASL Vulnerability Allows Username Enumeration Attacks

First seen 26 May 2026, 12:07 UTC GbhackersCybersecuritynewsUbuntulaunchpad.net 93% similarity 57.8

Article Content

Browse articles
ThreatCluster

A timing side-channel vulnerability in Memcached's SASL authentication mechanism, tracked as CVE-2026-47783, has been disclosed. This flaw affects versions prior to 1.6.42 and enables attackers to enumerate valid usernames. The vulnerability was confirmed by researchers and poses a significant risk to systems using Memcached for password database authentication. The flaw was addressed in the latest release, which includes multiple critical bug fixes. Security professionals are urged to update their systems to mitigate potential exploitation. The vulnerability was published on May 20, 2026.

Key Points: • CVE-2026-47783 allows username enumeration via a timing side-channel attack. • Affected versions of Memcached are those prior to 1.6.42. • The vulnerability was patched in the recent Memcached update released on May 20, 2026.

ThreatCluster AI

Timeline

2026-05-20
CVE-2026-47783 published
A timing side-channel vulnerability in Memcached's SASL authentication was disclosed, affecting versions before 1.6.42.
Gbhackers
2026-05-26
Memcached version 1.6.42 released
A security-focused update was released to address CVE-2026-47783 and other critical bugs.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story