Description
An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.papercut.com/kb/Main/security-bulletin-sep-2026/ |
|
History
Thu, 24 Sep 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings. | |
| Title | PaperCut NG/MF: Remote Code Execution via Scan2Fax | |
| Weaknesses | CWE-22 CWE-78 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: PaperCut
Published:
Updated: 2026-09-24T06:43:35.197Z
Reserved: 2026-08-28T00:13:21.684Z
Link: CVE-2026-82077
No data.
Status : Received
Published: 2026-09-24T07:16:33.457
Modified: 2026-09-24T07:16:33.457
Link: CVE-2026-82077
No data.
OpenCVE Enrichment
No data.