Vulnerability record · CVE-2023-39143 · published 4 August 2023
CVE-2023-39143: PaperCut NG/MF Windows path traversal enables file upload and RCE
Papercut · Papercut Mf
PaperCut NG and PaperCut MF before 22.1.3 on Windows are vulnerable to path traversal, allowing attackers to upload, read, or delete arbitrary files. When external device integration is enabled, a common configuration, this escalates to remote code execution.
Description
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated network exploitation, high EPSS, public exploit references, and potential for remote code execution make this a critical risk.
What it is
PaperCut NG and PaperCut MF before 22.1.3 on Windows are vulnerable to path traversal, allowing attackers to upload, read, or delete arbitrary files. When external device integration is enabled, a common configuration, this escalates to remote code execution.
Impact
An unauthenticated attacker can read or delete arbitrary files and, with external device integration enabled, execute code on the server. This can lead to full compromise of the PaperCut host.
Attack surface
The flaw is reachable over the network without authentication or user interaction, as reflected by the CVSS vector AV:N/AC:L/PR:N/UI:N. Exploitation requires the target to be a Windows installation of PaperCut NG or MF before 22.1.3, and RCE specifically requires external device integration to be enabled.
Exploitation
The record is not listed in CISA KEV, but EPSS is very high (0.806, 99.6th percentile) and public exploit references are tagged Exploit, indicating active interest and likely weaponization.
What to do
- Upgrade PaperCut NG and PaperCut MF to version 22.1.3 or later on Windows immediately.
- If patching is not immediately possible, disable external device integration where feasible to remove the RCE path.
- Restrict network access to PaperCut web interfaces to trusted management networks only.
- Monitor and review file system changes in PaperCut installation and data directories for unexpected uploads or deletions.
Detection
- Monitor web server logs for path traversal patterns (e.g., ../) targeting PaperCut endpoints.
- Alert on unexpected file creation or modification in PaperCut application directories, especially executable or script files.
- Review process creation events for child processes spawned by the PaperCut service (e.g., cmd.exe, powershell.exe).
- Track authentication and access logs for anomalous requests to PaperCut administrative or device integration endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/ | ExploitThird Party Advisory |
| https://www.papercut.com/kb/Main/securitybulletinjuly2023/ | Vendor Advisory |
| https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/ | ExploitThird Party Advisory |
| https://www.papercut.com/kb/Main/securitybulletinjuly2023/ | Vendor Advisory |
Track CVE-2023-39143 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-39143), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.