Executive brief
PaperCut NG/MF is a server application that manages printing and document workflows in enterprise environments. An unsafe reflection vulnerability allows attackers to execute arbitrary code with the privileges of the PaperCut server, potentially compromising the entire printing infrastructure and gaining access to sensitive document and billing data.
Technical details
This vulnerability exploits unsafe Java reflection mechanisms within PaperCut NG/MF that allow attackers to access and manipulate system configuration parameters without proper validation. The flaw enables execution of arbitrary Java bytecode that is already present on the application classpath, running under the security context of the PaperCut server process. The vulnerability can be chained with CVE-2026-81578 for compound impact. An attacker can manipulate application behavior and achieve remote code execution by leveraging Java's reflection APIs to invoke arbitrary methods or instantiate malicious classes. No patch status is specified in the advisory details provided.
Affected products
- PaperCut PaperCut NG/MF
Timeline
- 2026-08-31: disclosed
- exploited: Reported exploited in the wild