Junglewise Threat Intelligence

CVE-2026-6180: PaperCut MF race condition in HP badge-swipe processing

CVE-2026-6180 · Severity: high · CVSS 8.1 · Published 2026-05-05

Executive brief

A security vulnerability exists in PaperCut MF and NG print management software when used with certain HP multifunction printers. Under specific network conditions, the system may incorrectly process badge-swipe data, leading to a truncated user ID. In environments using custom ID processing scripts, this can allow an attacker to be logged in as a different user, potentially gaining unauthorized access to sensitive documents or administrative functions on the printing device.

Technical details

A race condition (CWE-367) exists in the way PaperCut MF and NG process fragmented badge-swipe data from specific HP multifunction devices. When network conditions involve dropped packets and out-of-order sequence counters, the server may fail to receive a sequence reset notification, causing it to reject initial data chunks while erroneously accepting subsequent ones. This results in the registration of a truncated badge ID string. If the environment uses custom badge-ID post-processing scripts, this truncated string can be transformed into a valid ID for a different user, leading to an 'Incorrect User Login' and unauthorized session establishment. The vulnerability is reachable over the network but requires specific timing and network conditions (High Attack Complexity). Fixed versions include 24.1.9 and 25.0.10.

Affected products

  • PaperCut PaperCut MF up to (excluding) 24.1.9, from (including) 25.0.2 up to (excluding) 25.0.10
  • PaperCut PaperCut NG up to (excluding) 24.1.9, from (including) 25.0.2 up to (excluding) 25.0.10

Timeline

  • 2026-05-05: advisory: Initial advisory published by PaperCut
  • 2026-05-12: other: NIST initial analysis and CVSS scoring completed

References

Related threats