Executive brief
PaperCut NG and MF are print management solutions used by organizations to manage and secure printing. A critical security flaw allows unauthorized individuals to bypass login requirements and gain administrative access to the system over the network. This could lead to the exposure of sensitive print data or unauthorized changes to system configurations.
Technical details
This vulnerability is classified as Improper Authentication (CWE-287) within the SecurityRequestFilter class of PaperCut NG and MF. The flaw stems from an improper implementation of the authentication algorithm, which allows a remote, unauthenticated attacker to bypass security checks via specially crafted network requests. Successful exploitation grants the attacker administrative access to the application interface. This vulnerability has been observed being exploited in the wild. Patches are available in versions 20.1.7, 21.2.11, 22.0.9, and later.
Affected products
- PaperCut PaperCut MF 15.0.0 to 20.1.6, 21.0.0 to 21.2.10, 22.0.0 to 22.0.8
- PaperCut PaperCut NG 15.0.0 to 20.1.6, 21.0.0 to 21.2.10, 22.0.0 to 22.0.8
Timeline
- 2023-04-20: disclosed: Initial disclosure by Zero Day Initiative
- 2026-04-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2026-04-20: exploited: Confirmed active exploitation in the wild