Unsafe Dynamic Class Loading in PaperCut MF and NG Database Connection Utilities
CVE-2026-82078
9.4CRITICAL
What is CVE-2026-82078?
An unsafe dynamic class loading vulnerability exists within the database connection utilities of PaperCut MF and PaperCut NG. This issue arises from the application instantiating database driver classes based solely on configurable driver names, without adequately validating these against a whitelist of approved drivers. As a result, if an attacker successfully manipulates system configuration parameters, they can execute arbitrary Java bytecode on the application classpath, which operates under the security context of the PaperCut server process. This could potentially lead to severe security breaches within the affected systems.
Affected Version(s)
PaperCut MF/NG 0 < 24.1.10, 25.0.13, 26.0.5
