Description
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
Published: 2026-08-28
Score: 8.8 High
EPSS: 3.3% Low
KEV: Yes
Impact: Unauthorized configuration modification
Action: Apply Patch
AI Analysis

Impact

An improper access control flaw in the web management interface of PaperCut MF and PaperCut NG permits an unauthenticated attacker to invoke certain administrative operations before the system completes its access validation. The flaw allows the attacker to alter system configuration settings without authentication, effectively bypassing the intended authorization controls.

Affected Systems

PaperCut’s PaperCut MF and PaperCut NG products are affected. No specific version range is listed in the vendor advisories, so all deployed installations are potentially vulnerable until a patch is applied.

Risk and Exploitability

The vulnerability scores a high CVSS of 8.8, indicating substantial impact if exploited. The EPSS score is less than 1%, indicating a low but non‑zero exploitation probability. It is now listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector likely requires the ability to send HTTP requests to the web management interface, which can be reachable from external networks unless protected by network segmentation. Given the lack of known exploitation reports, the likelihood remains uncertain, but the high severity and the KEV status warrant prompt action.

Generated by OpenCVE AI on August 31, 2026 at 15:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PaperCut MF and PaperCut NG to the latest vendor-released patch as described in the official advisory.
  • Ensure the web management interface is not publicly exposed; restrict it to trusted networks or secure it behind a VPN or firewall with network‑level authentication.
  • As a temporary mitigative measure, disable or tightly restrict any administrative endpoints that can be accessed without authentication, following vendor guidance.
  • Monitor audit logs for unexpected configuration changes and investigate any anomalous activity promptly.

Generated by OpenCVE AI on August 31, 2026 at 15:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Papercut
Papercut papercut Mf
Papercut papercut Ng
CPEs cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*
Vendors & Products Papercut
Papercut papercut Mf
Papercut papercut Ng
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Mon, 31 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 15:30:00 +0000


Mon, 31 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-08-28T00:00:00+00:00', 'dueDate': '2026-09-11T00:00:00+00:00'}


Mon, 31 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 29 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
Title PaperCut MF/NG: Authentication Bypass
Weaknesses CWE-305
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Papercut Papercut Mf Papercut Ng
cve-icon MITRE

Status: PUBLISHED

Assigner: PaperCut

Published:

Updated: 2026-09-13T23:15:33.997Z

Reserved: 2026-08-27T07:34:07.363Z

Link: CVE-2026-81578

cve-icon Vulnrichment

Updated: 2026-08-28T15:43:43.426Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-28T16:18:29.600

Modified: 2026-09-14T00:16:56.207

Link: CVE-2026-81578

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T21:24:40Z

Weaknesses
  • CWE-305

    Authentication Bypass by Primary Weakness