Vulnerability record · CVE-2026-81578 · published 28 August 2026
CVE-2026-81578: PaperCut MF/NG web interface access control flaw allows unauthenticated config changes
Papercut · Papercut Mf
PaperCut MF and NG contain an improper access control flaw in the web management interface where unauthenticated remote requests to administrative functions can trigger backend actions before access validation completes. This lets an unauthenticated attacker modify certain system configurations, which matters because the product is widely deployed and the flaw is listed in CISA KEV.
Description
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityThe flaw is unauthenticated, remotely reachable, allows configuration modification, and is listed in CISA KEV with a short remediation deadline.
What it is
PaperCut MF and NG contain an improper access control flaw in the web management interface where unauthenticated remote requests to administrative functions can trigger backend actions before access validation completes. This lets an unauthenticated attacker modify certain system configurations, which matters because the product is widely deployed and the flaw is listed in CISA KEV.
Impact
An unauthenticated remote attacker can change certain system configurations, with the CVSS vector indicating high integrity impact and low confidentiality and availability impact. The attacker does not gain full administrative control based on the record, but configuration tampering can weaken defenses or disrupt printing services.
Attack surface
Reachable over the network through the web management interface, with no authentication and no user interaction required per the CVSS vector (AV:N/PR:N/UI:N). Any internet-exposed or internally reachable management interface is a candidate target.
Exploitation
CISA added this to KEV on 2026-08-31 with a remediation due date of 2026-09-14, indicating known exploitation in the wild. EPSS is 0.0329 (87.9th percentile), and a Metasploit pull request reference suggests public exploit tooling activity, though the record does not confirm a released module.
What to do
- Apply the vendor patch from the PaperCut security bulletin dated 27 Aug 2026 as the first action.
- If patching cannot be completed immediately, restrict access to the PaperCut web management interface to trusted networks and block internet exposure.
- Follow CISA BOD 26-04 guidance, including the option to discontinue use of the product if mitigations are unavailable.
- Review and restore system configurations for signs of unauthorized modification after exposure.
- Track the CISA KEV due date of 2026-09-14 to confirm remediation is complete.
Detection
- Review web server and application logs for unauthenticated requests to administrative endpoints that returned success or triggered backend actions.
- Monitor for unexpected changes to PaperCut system configuration and alert on modifications outside change windows.
- Hunt for requests matching known exploit patterns from the Metasploit pull request reference against the management interface.
- Baseline and alert on access to the management interface from untrusted or external source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-81578 to the Known Exploited Vulnerabilities catalog on 31 August 2026 as "PaperCut NG/MF Missing Authentication for Critical Function Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 14 September 2026.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ | PatchVendor Advisory |
| https://github.com/rapid7/metasploit-framework/pull/21842 | Issue TrackingPatch |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81578 | PatchThird Party AdvisoryUS Government Resource |
Track CVE-2026-81578 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-81578), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.