PT-2026-83117 · Papercut · Papercut Mf+1

CVE-2026-81578

·

Published

2026-08-27

·

Updated

2026-09-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PaperCut MF (affected versions not specified) PaperCut NG (affected versions not specified)
Description An improper access control issue exists in the web management interface. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions before access validation checks are completed, allowing an unauthenticated remote attacker to modify certain system configurations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81578

Affected Products

Papercut Mf
Papercut Ng