Description
An issue was discovered in the PaperCut Hive Ricoh embedded application. When the "Deep Logging" (diagnostic) mode is enabled, the application inadvertently records administrative credentials in plain text within the log files.



An attacker with administrative access to the PaperCut Hive management portal could remotely enable deep logging and subsequently retrieve sensitive device passwords from the logs after an authorized user authenticates at the device. This exposure allows for the lateral movement or unauthorized configuration of the physical print hardware.
Published: 2026-05-05
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An issue with the PaperCut Hive Ricoh embedded application causes administrative credentials to be recorded in plain text within log files when Deep Logging mode is enabled. This flaw is a classic example of CWE‑532, where sensitive information is inadvertently persisted in logs. The consequence is confidentiality loss, allowing attackers to obtain device passwords that could be used to reconfigure or otherwise compromise the physical print hardware.

Affected Systems

The vulnerability affects the PaperCut Hive product from PaperCut. No specific affected version numbers are supplied in the advisory, so any installation that supports Deep Logging should be considered at risk until a vendor update is applied.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. The advisory does not provide an EPSS score, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited commercial exploitation so far. However, exploitation requires an attacker to have administrative access to the PaperCut Hive management portal to enable Deep Logging; once active, any subsequent legitimate user login will generate logs containing the passwords, which the attacker can harvest. This lateral capability can enable unauthorized configuration or remote control of the physical print devices.

Generated by OpenCVE AI on May 5, 2026 at 08:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to a version that removes plain text password logging
  • Immediately disable Deep Logging mode in the PaperCut Hive management portal
  • Restrict administrative access to the management portal to trusted personnel only

Generated by OpenCVE AI on May 5, 2026 at 08:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 06 May 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Papercut
Papercut papercut Hive
Vendors & Products Papercut
Papercut papercut Hive

Tue, 05 May 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 05 May 2026 07:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in the PaperCut Hive Ricoh embedded application. When the "Deep Logging" (diagnostic) mode is enabled, the application inadvertently records administrative credentials in plain text within the log files. An attacker with administrative access to the PaperCut Hive management portal could remotely enable deep logging and subsequently retrieve sensitive device passwords from the logs after an authorized user authenticates at the device. This exposure allows for the lateral movement or unauthorized configuration of the physical print hardware.
Title PaperCut Hive (Ricoh): Plain text password in logs
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Papercut Papercut Hive
cve-icon MITRE

Status: PUBLISHED

Assigner: PaperCut

Published:

Updated: 2026-05-05T12:41:06.788Z

Reserved: 2026-05-05T02:41:39.279Z

Link: CVE-2026-7824

cve-icon Vulnrichment

Updated: 2026-05-05T12:41:03.156Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-05T07:16:01.100

Modified: 2026-05-07T15:10:53.070

Link: CVE-2026-7824

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-06T09:21:53Z

Weaknesses