Executive brief
PaperCut NG/MF is a print and document management system widely used in organizations to control, monitor, and bill print jobs. This vulnerability allows attackers on the network to bypass authentication and modify critical system settings without needing valid credentials, potentially leading to unauthorized system control or service disruption. The vulnerability is actively being exploited in real-world attacks.
Technical details
This is an authentication bypass vulnerability in PaperCut NG/MF affecting a critical system function. The vulnerability allows unauthenticated remote attackers to access and modify system configurations that should require valid credentials. The attack vector is network-based with no authentication required from the attacker. The vulnerability has been observed being exploited in the wild and can be chained with CVE-2026-82078 to achieve greater impact on affected systems. Patch availability and detailed remediation guidance should be obtained from PaperCut's official security advisory.
Affected products
- PaperCut PaperCut NG <UNKNOWN>
- PaperCut PaperCut MF <UNKNOWN>
Timeline
- 2026-08-31: disclosed
- exploited: Exploited in the wild