Sensitive Credential Exposure in PaperCut Hive by PaperCut
CVE-2026-7824

5.9MEDIUM

Key Information:

Vendor

Papercut

Vendor
CVE Published:
5 May 2026

What is CVE-2026-7824?

A security issue has been identified in the PaperCut Hive Ricoh embedded application. When the 'Deep Logging' feature is activated for diagnostic purposes, the application can unintentionally log sensitive administrative credentials in plain text. This vulnerability enables an attacker with administrative access to the PaperCut Hive management portal to enable deep logging remotely. Following an authorized user’s authentication at the device, the attacker can then retrieve sensitive passwords from the logs, which can lead to unauthorized configuration of physical print hardware and lateral movement within the network.

Affected Version(s)

PaperCut Hive 0 < 2.2.0

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hayden Moore
.