Improper Access Control Vulnerability in PaperCut MF and PaperCut NG
CVE-2026-81578

8.8HIGH

Key Information:

Vendor

Papercut

Vendor
CVE Published:
28 August 2026

Badges

📈 Trended📈 Score: 4,340💰 Ransomware👾 Exploit Exists🦅 CISA Reported📰 News Worthy

What is CVE-2026-81578?

CVE-2026-81578 is a vulnerability affecting the PaperCut MF and PaperCut NG software solutions, which are designed for print management across various organizational environments. This vulnerability pertains to improper access control within the web management interface of these systems. Specifically, it allows unauthenticated remote attackers to make requests that can inadvertently execute backend actions related to administrative functions without sufficient access verification. Consequently, this flaw can lead to unauthorized modifications of system configurations, potentially compromising the security and stability of the printing infrastructure within an organization. The impact of such unauthorized access could result in altered printing behaviors, unauthorized data exposure, and disruptions to operational workflows.

Potential impact of CVE-2026-81578

  1. Unauthorized Configuration Changes: Attackers can exploit the vulnerability to alter system settings, which can lead to misuse of printing resources, increased costs, and disruptions to normal printing operations.

  2. Compromised Data Integrity: With the ability to modify configurations, unauthorized access could facilitate data corruption or loss, impacting sensitive information managed through the PaperCut system.

  3. Increased Attack Surface: The vulnerability may serve as a gateway for further attacks within the organizational network, potentially leading to more severe security incidents or data breaches if not addressed promptly.

CISA has reported CVE-2026-81578

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-81578 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

PaperCut MF/NG 0 < 24.1.10

PaperCut MF/NG 25.0.0 < 25.0.13

PaperCut MF/NG 26.0.0 < 26.0.5

News Articles

Recently patched PaperCut zero-days used in data theft attacks

Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.

3 weeks ago

PaperCut Exploitation Escalates to Active Intrusions

PaperCut attacks exploiting CVE-2026-82078 and CVE-2026-81578 have escalated, with hackers performing hands-on-keyboard activity.

3 weeks ago

CISA Warns of Multiple PaperCut NG/MF Vulnerabilities Actively Exploited in Attacks

CISA has added two vulnerabilities affecting PaperCut NG and PaperCut MF to its KEV Catalog, warning that threat actors are actively exploiting the flaws in real-world attacks.

3 weeks ago

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 💰

    Used in Ransomware

  • 📈

    Vulnerability started trending

  • 👾

    Exploit known to exist

  • 🦅

    CISA Reported

  • 📰

    First article discovered by Cybersecurity Dive

  • Vulnerability published

  • Vulnerability Reserved

.