Description
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
Published: 2026-08-28
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper access control flaw in the web management interface of PaperCut MF and PaperCut NG permits an unauthenticated attacker to invoke certain administrative operations before the system completes its access validation. The flaw allows the attacker to alter system configuration settings without authentication, effectively bypassing the intended authorization controls.

Affected Systems

PaperCut’s PaperCut MF and PaperCut NG products are affected. No specific version range is listed in the vendor advisories, so all deployed installations are potentially vulnerable until a patch is applied.

Risk and Exploitability

The vulnerability scores a high CVSS of 8.8, indicating substantial impact if exploited. EPSS data is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector likely requires the ability to send HTTP requests to the web management interface, which can be reachable from external networks unless protected by network segmentation. Given the lack of known exploitation reports, the likelihood remains uncertain, but the high severity and lack of mitigation in older deployments warrant prompt action.

Generated by OpenCVE AI on August 28, 2026 at 16:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PaperCut MF and PaperCut NG to the latest vendor-released patch as described in the official advisory.
  • Ensure the web management interface is not publicly exposed; restrict it to trusted networks or secure it behind a VPN or firewall with network‑level authentication.
  • As a temporary mitigative measure, disable or tightly restrict any administrative endpoints that can be accessed without authentication, following vendor guidance.
  • Monitor audit logs for unexpected configuration changes and investigate any anomalous activity promptly.

Generated by OpenCVE AI on August 28, 2026 at 16:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
Title PaperCut MF/NG: Authentication Bypass
Weaknesses CWE-305
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: PaperCut

Published:

Updated: 2026-08-28T15:43:46.723Z

Reserved: 2026-08-27T07:34:07.363Z

Link: CVE-2026-81578

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T16:18:29.600

Modified: 2026-08-28T20:20:11.350

Link: CVE-2026-81578

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T17:00:13Z

Weaknesses
  • CWE-305

    Authentication Bypass by Primary Weakness