Junglewise Threat Intelligence

CVE-2026-6418: PaperCut MF and NG path traversal in Shared Account Synchronization

CVE-2026-6418 · Severity: medium · CVSS 4.9 · Published 2026-05-05

Executive brief

PaperCut MF and NG are print management solutions used to control and monitor printing across organizations. A vulnerability in the account synchronization feature allows an administrator to access sensitive files on the underlying server that they should not be able to see. This could lead to the exposure of system configuration details or other confidential data, potentially aiding further attacks on the infrastructure.

Technical details

A path traversal vulnerability (CWE-36) exists in the Shared Account Synchronization component of PaperCut MF and NG. The application fails to properly validate or sanitize the source path provided for account data synchronization. An authenticated attacker with administrative privileges can specify arbitrary local file paths, causing the application to parse and display the contents of those files within the management interface. This allows for directory enumeration and the unauthorized reading of sensitive text-based system or configuration files, limited by the permissions of the service account running the PaperCut application. The issue is addressed in version 25.0.11.

Affected products

  • PaperCut PaperCut MF up to (excluding) 25.0.11
  • PaperCut PaperCut NG up to (excluding) 25.0.11

Timeline

  • 2026-05-05: disclosed: Initial disclosure of the vulnerability.
  • 2026-05-05: advisory: PaperCut released a security bulletin.
  • 2026-05-12: other: NVD analysis and CPE information added.

References

Related threats