← Vulnerability feed

Vulnerability record · CVE-2023-39143 · published 4 August 2023

CVE-2023-39143: PaperCut NG/MF Windows path traversal enables file upload and RCE

Papercut · Papercut Mf

PaperCut NG and PaperCut MF before 22.1.3 on Windows are vulnerable to path traversal, allowing attackers to upload, read, or delete arbitrary files. When external device integration is enabled, a common configuration, this escalates to remote code execution.

9.8 CVSS 3.1 Critical EPSS 80% · top 0.4% CWE-22 · Path traversal
9.8CVSS 3.1 base score
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated network exploitation, high EPSS, public exploit references, and potential for remote code execution make this a critical risk.

What it is

PaperCut NG and PaperCut MF before 22.1.3 on Windows are vulnerable to path traversal, allowing attackers to upload, read, or delete arbitrary files. When external device integration is enabled, a common configuration, this escalates to remote code execution.

Impact

An unauthenticated attacker can read or delete arbitrary files and, with external device integration enabled, execute code on the server. This can lead to full compromise of the PaperCut host.

Attack surface

The flaw is reachable over the network without authentication or user interaction, as reflected by the CVSS vector AV:N/AC:L/PR:N/UI:N. Exploitation requires the target to be a Windows installation of PaperCut NG or MF before 22.1.3, and RCE specifically requires external device integration to be enabled.

Exploitation

The record is not listed in CISA KEV, but EPSS is very high (0.806, 99.6th percentile) and public exploit references are tagged Exploit, indicating active interest and likely weaponization.

What to do

  • Upgrade PaperCut NG and PaperCut MF to version 22.1.3 or later on Windows immediately.
  • If patching is not immediately possible, disable external device integration where feasible to remove the RCE path.
  • Restrict network access to PaperCut web interfaces to trusted management networks only.
  • Monitor and review file system changes in PaperCut installation and data directories for unexpected uploads or deletions.

Detection

  • Monitor web server logs for path traversal patterns (e.g., ../) targeting PaperCut endpoints.
  • Alert on unexpected file creation or modification in PaperCut application directories, especially executable or script files.
  • Review process creation events for child processes spawned by the PaperCut service (e.g., cmd.exe, powershell.exe).
  • Track authentication and access logs for anomalous requests to PaperCut administrative or device integration endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-39143 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27350PaperCut NG/MF improper access control allows auth bypass and RCEPaperCut NG and MF contain an improper access control flaw in the SetupCompleted class that lets an unauthenticated remote attacker bypass authentica…KEVEPSS 100%analysed9.4CVE-2026-82078PaperCut MF/NG unsafe dynamic class loading enables code executionPaperCut MF and NG instantiate database driver classes from configurable driver names without validating them against an allowlist of approved driver…KEVEPSS 3.8%analysed8.8CVE-2026-81578PaperCut MF/NG web interface access control flaw allows unauthenticated config changesPaperCut MF and NG contain an improper access control flaw in the web management interface where unauthenticated remote requests to administrative fu…KEVEPSS 4.5%analysed8.8CVE-2023-2533PaperCut NG/MF CSRF allows admin security setting changes and code executionPaperCut NG and MF contain a cross-site request forgery flaw that, under specific conditions, lets an attacker change security settings or execute ar…KEVEPSS 29%analysed7.5CVE-2023-27351PaperCut NG/MF authentication bypass in SecurityRequestFilterPaperCut NG and MF contain an improper authentication flaw in the SecurityRequestFilter class caused by a faulty authentication algorithm implementat…KEVEPSS 78%analysed9.8CVE-2024-1222PaperCut NG/MF API privilege escalation via crafted requestA subset of PaperCut NG and MF API calls can be reached with a maliciously formed request that grants an API authorization level with elevated privil…EPSS 64%analysed9.8CVE-2019-12135Papercut mf vulnerabilityAn unspecified vulnerability in the application server in PaperCut MF and NG versions 18.3.8 and earlier and versions 19.0.3 and earlier allows remot…EPSS 2.5%9.8CVE-2019-8948Papercut mf injection vulnerabilityPaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2023-39143), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.