Insecure Process Execution in PaperCut Print Deploy Client for Windows
CVE-2026-6645

7.3HIGH

Key Information:

Vendor

Papercut

Vendor
CVE Published:
22 June 2026

What is CVE-2026-6645?

A vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows that allows local attackers to exploit an insecure process execution flaw. The client, which generally operates with elevated system privileges, performs an internal validation check by calling a secondary utility without specifying an absolute file path. This omission can be exploited by an attacker who has the ability to modify the system's search path. By placing a malicious binary in the expected search order, the attacker can execute their code with SYSTEM privileges, leading to a full compromise of the affected host.

Affected Version(s)

Print Deploy Windows 0 < 1.10.4178

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex F. <support.solutions@jet-services.com> // JET Services
.