Impact
An improper access control flaw in the web management interface of PaperCut MF and PaperCut NG permits an unauthenticated attacker to invoke certain administrative operations before the system completes its access validation. The flaw allows the attacker to alter system configuration settings without authentication, effectively bypassing the intended authorization controls.
Affected Systems
PaperCut’s PaperCut MF and PaperCut NG products are affected. No specific version range is listed in the vendor advisories, so all deployed installations are potentially vulnerable until a patch is applied.
Risk and Exploitability
The vulnerability scores a high CVSS of 8.8, indicating substantial impact if exploited. EPSS data is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector likely requires the ability to send HTTP requests to the web management interface, which can be reachable from external networks unless protected by network segmentation. Given the lack of known exploitation reports, the likelihood remains uncertain, but the high severity and lack of mitigation in older deployments warrant prompt action.
OpenCVE Enrichment