CVE-2026-81578
8.8PaperCut · PaperCut MF/NG
An improper access control flaw in PaperCut MF/NG allows unauthenticated remote attackers to modify system configurations by bypassing validation checks for administrative functions.
Executive summary
A high-severity authentication bypass vulnerability in PaperCut MF and PaperCut NG allows unauthenticated remote attackers to modify critical system configurations.
Vulnerability
The vulnerability is an authentication bypass (CWE-305) occurring in the web management interface, where unauthenticated remote requests targeting administrative functions trigger backend actions before access validation completes.
Business impact
The ability for an unauthenticated attacker to modify system configurations poses a severe risk to organizational infrastructure. With a CVSS score of 8.8, this vulnerability carries significant potential for unauthorized administrative control, which could lead to service disruption, credential compromise, or the establishment of persistence within the print management environment.
Remediation
Immediate Action: Update all instances of PaperCut MF or NG to version 24.1.10, 25.0.13, 26.0.5, or later immediately to resolve the access control flaw.
Proactive Monitoring: Review web management interface access logs for unusual administrative requests or configuration changes originating from unauthorized or external IP addresses.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized access attempts to administrative endpoints of the PaperCut management interface until patches can be applied.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the ease of exploitability and the potential for full administrative configuration compromise, this vulnerability should be prioritized for immediate remediation. Organizations must ensure that all affected PaperCut servers are updated to the specified patched versions to prevent unauthorized access and potential system hijacking.