PT-2023-2482 · Unknown · Papercut Ng

CVE-2023-27350

·

Published

2023-03-14

·

Updated

2026-09-05

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PaperCut MF versions prior to 20.1.7 PaperCut MF versions prior to 21.2.11 PaperCut MF versions prior to 22.0.9 PaperCut NG versions prior to 20.1.7 PaperCut NG versions prior to 21.2.11 PaperCut NG versions prior to 22.0.9 PaperCut NG version 22.0.5 (Build 63914) PaperCut MF (affected versions not specified) PaperCut NG (affected versions not specified)
Description Improper access control in the SetupCompleted class allows unauthenticated remote attackers to bypass authentication and execute arbitrary code in the context of SYSTEM. The issue is exploited by abusing Apache Tapestry's direct request format, specifically targeting endpoints such as /app?service=direct/1/Error/ConfigEditor/quickFindForm. By manipulating these requests, attackers can invoke privileged components like ConfigEditor and UserList while the system only validates the displayed Error or Exception page.
Technical exploitation involves rewriting configuration keys—specifically user-lookup.db-driver, user-lookup.db-url, user-lookup.id-to-username-sql, and user-lookup.enabled—to point to a malicious H2 JDBC URL. This chain leverages the bundled Apache Derby driver and the Nashorn JavaScript engine to create a database trigger that launches operating-system processes. This flaw has been actively exploited in the wild by ransomware operators, including LockBit and Clop, primarily targeting enterprise organizations and educational institutions.
Recommendations Update PaperCut MF and PaperCut NG to versions 20.1.7, 21.2.11, or 22.0.9 respectively, depending on the current version branch. Apply the emergency patches released on August 28, 2026, for versions 25 and 26. Restrict external access to the PaperCut Application Server web interfaces to minimize the risk of exploitation.

Exploit

Fix

RCE

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02273
CVE-2023-27350
ZDI-23-233

Affected Products

Papercut Ng