← Vulnerability feed

Vulnerability record · CVE-2026-81578 · published 28 August 2026

CVE-2026-81578: PaperCut MF/NG web interface access control flaw allows unauthenticated config changes

Papercut · Papercut Mf

PaperCut MF and NG contain an improper access control flaw in the web management interface where unauthenticated remote requests to administrative functions can trigger backend actions before access validation completes. This lets an unauthenticated attacker modify certain system configurations, which matters because the product is widely deployed and the flaw is listed in CISA KEV.

8.8 CVSS 4.0 High CISA KEV since 31 Aug 2026 EPSS 4.5% · top 8.9% CWE-305 · CWE-305
8.8CVSS 4.0 base score
4.5%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References
14 Sep 2026Last modified by NVD

Description

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw is unauthenticated, remotely reachable, allows configuration modification, and is listed in CISA KEV with a short remediation deadline.

What it is

PaperCut MF and NG contain an improper access control flaw in the web management interface where unauthenticated remote requests to administrative functions can trigger backend actions before access validation completes. This lets an unauthenticated attacker modify certain system configurations, which matters because the product is widely deployed and the flaw is listed in CISA KEV.

Impact

An unauthenticated remote attacker can change certain system configurations, with the CVSS vector indicating high integrity impact and low confidentiality and availability impact. The attacker does not gain full administrative control based on the record, but configuration tampering can weaken defenses or disrupt printing services.

Attack surface

Reachable over the network through the web management interface, with no authentication and no user interaction required per the CVSS vector (AV:N/PR:N/UI:N). Any internet-exposed or internally reachable management interface is a candidate target.

Exploitation

CISA added this to KEV on 2026-08-31 with a remediation due date of 2026-09-14, indicating known exploitation in the wild. EPSS is 0.0329 (87.9th percentile), and a Metasploit pull request reference suggests public exploit tooling activity, though the record does not confirm a released module.

What to do

  • Apply the vendor patch from the PaperCut security bulletin dated 27 Aug 2026 as the first action.
  • If patching cannot be completed immediately, restrict access to the PaperCut web management interface to trusted networks and block internet exposure.
  • Follow CISA BOD 26-04 guidance, including the option to discontinue use of the product if mitigations are unavailable.
  • Review and restore system configurations for signs of unauthorized modification after exposure.
  • Track the CISA KEV due date of 2026-09-14 to confirm remediation is complete.

Detection

  • Review web server and application logs for unauthenticated requests to administrative endpoints that returned success or triggered backend actions.
  • Monitor for unexpected changes to PaperCut system configuration and alert on modifications outside change windows.
  • Hunt for requests matching known exploit patterns from the Metasploit pull request reference against the management interface.
  • Baseline and alert on access to the management interface from untrusted or external source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-81578 to the Known Exploited Vulnerabilities catalog on 31 August 2026 as "PaperCut NG/MF Missing Authentication for Critical Function Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 14 September 2026.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-81578 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27350PaperCut NG/MF improper access control allows auth bypass and RCEPaperCut NG and MF contain an improper access control flaw in the SetupCompleted class that lets an unauthenticated remote attacker bypass authentica…KEVEPSS 100%analysed9.4CVE-2026-82078PaperCut MF/NG unsafe dynamic class loading enables code executionPaperCut MF and NG instantiate database driver classes from configurable driver names without validating them against an allowlist of approved driver…KEVEPSS 3.8%analysed8.8CVE-2023-2533PaperCut NG/MF CSRF allows admin security setting changes and code executionPaperCut NG and MF contain a cross-site request forgery flaw that, under specific conditions, lets an attacker change security settings or execute ar…KEVEPSS 29%analysed7.5CVE-2023-27351PaperCut NG/MF authentication bypass in SecurityRequestFilterPaperCut NG and MF contain an improper authentication flaw in the SecurityRequestFilter class caused by a faulty authentication algorithm implementat…KEVEPSS 78%analysed9.8CVE-2024-1222PaperCut NG/MF API privilege escalation via crafted requestA subset of PaperCut NG and MF API calls can be reached with a maliciously formed request that grants an API authorization level with elevated privil…EPSS 64%analysed9.8CVE-2023-39143PaperCut NG/MF Windows path traversal enables file upload and RCEPaperCut NG and PaperCut MF before 22.1.3 on Windows are vulnerable to path traversal, allowing attackers to upload, read, or delete arbitrary files.…EPSS 80%analysed9.8CVE-2019-12135Papercut mf vulnerabilityAn unspecified vulnerability in the application server in PaperCut MF and NG versions 18.3.8 and earlier and versions 19.0.3 and earlier allows remot…EPSS 2.5%9.8CVE-2019-8948Papercut mf injection vulnerabilityPaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2026-81578), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.