Unsafe Dynamic Class Loading in PaperCut MF and NG Database Connection Utilities
CVE-2026-82078

9.4CRITICAL

Key Information:

Vendor

Papercut

Vendor
CVE Published:
28 August 2026

What is CVE-2026-82078?

An unsafe dynamic class loading vulnerability exists within the database connection utilities of PaperCut MF and PaperCut NG. This issue arises from the application instantiating database driver classes based solely on configurable driver names, without adequately validating these against a whitelist of approved drivers. As a result, if an attacker successfully manipulates system configuration parameters, they can execute arbitrary Java bytecode on the application classpath, which operates under the security context of the PaperCut server process. This could potentially lead to severe security breaches within the affected systems.

Affected Version(s)

PaperCut MF/NG 0 < 24.1.10, 25.0.13, 26.0.5

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.