PT-2026-83117 · Papercut · Papercut Mf+1
CVE-2026-81578
·
Published
2026-08-27
·
Updated
2026-09-11
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PaperCut MF (affected versions not specified)
PaperCut NG (affected versions not specified)
Description
An improper access control issue exists in the web management interface. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions before access validation checks are completed, allowing an unauthenticated remote attacker to modify certain system configurations.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Papercut Mf
Papercut Ng