Improper Access Control Vulnerability in PaperCut MF and PaperCut NG
CVE-2026-81578

8.8HIGH

Key Information:

Vendor

Papercut

Vendor
CVE Published:
28 August 2026

What is CVE-2026-81578?

An improper access control vulnerability has been identified in the web management interface of PaperCut MF and PaperCut NG. This vulnerability allows unauthenticated remote requests to execute administrative functions without proper validation, which can result in unauthorized modifications to system configurations. Attackers may exploit this weakness to manipulate backend actions, highlighting the critical need for timely updates and security measures.

Affected Version(s)

PaperCut MF/NG 0 < 24.1.10, 25.0.13, 26.0.5

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.