CVE-2026-87739
6.9PaperCut · PaperCut NG/MF
PaperCut NG/MF contains an improper authentication vulnerability that allows unauthenticated, remote attackers to trigger report generation and access sensitive information.
Executive summary
A critical authentication bypass vulnerability in PaperCut NG/MF allows unauthenticated remote attackers to access sensitive report data.
Vulnerability
The application is susceptible to an authorization bypass (CWE-639) where user-controlled keys allow an unauthenticated, remote attacker to trigger report generation functions without valid credentials.
Business impact
The ability for an unauthenticated attacker to generate and view unauthorized reports poses a significant risk to data confidentiality. With a CVSS score of 6.9, this vulnerability could allow unauthorized parties to harvest sensitive print logs, user activity, or system configuration data, potentially leading to further reconnaissance or operational disruption.
Remediation
Immediate Action: Update PaperCut NG/MF to version 25.0.13 or 26.0.5 immediately to resolve the authentication bypass.
Proactive Monitoring: Audit server access logs for anomalous report generation requests originating from unknown or unauthorized IP addresses.
Compensating Controls: Implement network-level restrictions to limit access to the PaperCut management interface to trusted administrative subnets until patching is completed.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the ease of access for unauthenticated remote attackers, organizations should treat this vulnerability with urgency. Administrators must verify their current version and apply the identified patches in 25.0.13 or 26.0.5 immediately to protect sensitive system data from unauthorized exposure.
More PaperCut CVEs
History
- Analyst report written