CVE-2026-23892Disclosure(octoprint / octoprint)

LOWCVSS 5.9 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up to and including 1.11.5 are affected by a (theoretical) timing attack vulnerability that allows API key extraction over the network. Due to using character based comparison that short-circuits on the first mismatched character during API key validation, rather than a cryptographical method with static runtime regardless of the point of mismatch, an attacker with network based access to an affected OctoPrint could extract API keys valid on the instance by measuring the response times of the denied access responses and guess an API key character by character. The vulnerability is patched in version 1.11.6. The likelihood of this attack actually working is highly dependent on the network's latency, noise and similar parameters. An actual proof of concept was not achieved so far. Still, as always administrators are advised to not expose their OctoPrint instance on hostile networks, especially not on the public Internet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-208

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • octoprint

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
octoprint

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-01-27: 3Technical Details · 2026-01-27: 201-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23892 Timing-Based API Key Extraction Vulnerability in OctoPrint Web Interface https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23892

    Post summary

    CVE-2026-23892 is presented as a timing-based attack that can extract API keys from OctoPrint's web interface; it lacks any discussion of proof of concept, exploit code, active exploitation, or patch information.

    0000052
    4.0K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-23892: Tick-Tock-Pwn: Timing Side-Channels in OctoPrint A classic timing side-channel vulnerability in OctoPrint allows attackers on the local network to guess API keys character-by-character by measuring how long the server takes to say 'no'. https://cvereports.com/reports/CVE-2026-23892

    Post summary

    A timing side-channel in OctoPrint lets local network attackers guess API keys by measuring response delays.

    0000044
    29 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23892 OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up to and including 1.11.5 are affected by a (theoretical) timing attack v… https://www.cve.org/CVERecord?id=CVE-2026-23892

    Post summary

    CVE-2026-23892 is announced as a theoretical timing attack affecting OctoPrint up to version 1.11.5, with no PoC, exploit, active exploitation, patch, or detailed technical description provided.

    00000162
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appoctoprintoctoprint---

Explore more