Vulnerability record · CVE-2023-27350 · published 20 April 2023
CVE-2023-27350: PaperCut NG/MF improper access control allows auth bypass and RCE
Papercut · Papercut Mf
PaperCut NG and MF contain an improper access control flaw in the SetupCompleted class that lets an unauthenticated remote attacker bypass authentication. Successful exploitation leads to arbitrary code execution as SYSTEM, making it a severe risk for internet-facing print management servers.
Description
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution as SYSTEM, active exploitation, KEV listing with ransomware use, and near-maximum EPSS make this an urgent patch-first issue.
What it is
PaperCut NG and MF contain an improper access control flaw in the SetupCompleted class that lets an unauthenticated remote attacker bypass authentication. Successful exploitation leads to arbitrary code execution as SYSTEM, making it a severe risk for internet-facing print management servers.
Impact
An attacker gains full SYSTEM-level code execution on the PaperCut server without credentials. This can lead to complete host compromise, data theft, and use as a foothold for ransomware deployment.
Attack surface
Reachable over the network via the PaperCut web interface with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any exposed PaperCut NG/MF instance is directly attackable.
Exploitation
CISA added it to KEV on 2023-04-21 with known ransomware campaign use, and EPSS is near 1.0 (0.99999). Multiple public exploit references exist, indicating active and widespread exploitation.
What to do
- Apply the vendor updates referenced in PaperCut advisory PO-1216/PO-1219 immediately.
- Remove PaperCut servers from direct internet exposure and restrict access to trusted networks or VPN.
- If patching is delayed, apply vendor-provided mitigations and monitor for unauthorized administrative changes.
- Audit PaperCut server accounts and logs for signs of compromise, then rotate credentials and secrets.
- Block or alert on known exploit paths and suspicious child processes spawned by PaperCut services.
Detection
- Monitor PaperCut web logs for requests to SetupCompleted or unusual admin setup endpoints from unauthenticated clients.
- Alert on new processes spawned by PaperCut services, especially command shells or scripting interpreters.
- Hunt for unexpected creation of admin users, changes to print server configuration, or outbound connections from the PaperCut host.
- Correlate PaperCut server activity with ransomware precursor behaviors such as credential dumping or lateral movement.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-27350 to the Known Exploited Vulnerabilities catalog on 21 April 2023 as "PaperCut MF/NG Improper Access Control Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 12 May 2023.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-27350 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-27350), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.