PT-2023-2482 · Unknown · Papercut Ng
CVE-2023-27350
·
Published
2023-03-14
·
Updated
2026-09-05
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PaperCut MF versions prior to 20.1.7
PaperCut MF versions prior to 21.2.11
PaperCut MF versions prior to 22.0.9
PaperCut NG versions prior to 20.1.7
PaperCut NG versions prior to 21.2.11
PaperCut NG versions prior to 22.0.9
PaperCut NG version 22.0.5 (Build 63914)
PaperCut MF (affected versions not specified)
PaperCut NG (affected versions not specified)
Description
Improper access control in the
SetupCompleted class allows unauthenticated remote attackers to bypass authentication and execute arbitrary code in the context of SYSTEM. The issue is exploited by abusing Apache Tapestry's direct request format, specifically targeting endpoints such as /app?service=direct/1/Error/ConfigEditor/quickFindForm. By manipulating these requests, attackers can invoke privileged components like ConfigEditor and UserList while the system only validates the displayed Error or Exception page.Technical exploitation involves rewriting configuration keys—specifically
user-lookup.db-driver, user-lookup.db-url, user-lookup.id-to-username-sql, and user-lookup.enabled—to point to a malicious H2 JDBC URL. This chain leverages the bundled Apache Derby driver and the Nashorn JavaScript engine to create a database trigger that launches operating-system processes. This flaw has been actively exploited in the wild by ransomware operators, including LockBit and Clop, primarily targeting enterprise organizations and educational institutions.Recommendations
Update PaperCut MF and PaperCut NG to versions 20.1.7, 21.2.11, or 22.0.9 respectively, depending on the current version branch.
Apply the emergency patches released on August 28, 2026, for versions 25 and 26.
Restrict external access to the PaperCut Application Server web interfaces to minimize the risk of exploitation.
Exploit
Fix
RCE
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Papercut Ng