Unsafe Dynamic Class Loading in PaperCut MF and NG Database Connection Utilities
CVE-2026-82078
Key Information:
- Vendor
Papercut
- Status
- Vendor
- CVE Published:
- 28 August 2026
Badges
What is CVE-2026-82078?
CVE-2026-82078 is a significant vulnerability found in the database connection utilities of the PaperCut MF and NG software products, which are widely used for print management in organizational environments. This vulnerability arises from unsafe dynamic class loading practices that allow the application to instantiate database driver classes based solely on configurable driver names, without stringent validation against an allowlist of recognized drivers. Consequently, if an attacker gains access to manipulate system configuration settings, they can execute arbitrary Java bytecode within the security context of the PaperCut server process. This allows the potential for malicious activities, which can severely compromise the integrity and confidentiality of the entire system.
Potential Impact of CVE-2026-82078
-
Remote Code Execution: This vulnerability can lead to remote code execution, where attackers can run arbitrary code on the server. Given that this code operates under the security context of the PaperCut server, it could result in full control of the server environment, allowing attackers to manipulate sensitive data or conduct further intrusions.
-
Data Breaches: The exploitation of this vulnerability could facilitate unauthorized access to sensitive data transmitted through or stored within the PaperCut system. As organizations often store critical information related to user identities and organizational activities in these databases, a breach could have substantial ramifications for data privacy and regulatory compliance.
-
System Compromise and Network Propagation: Once exploited, the vulnerability can lead to a compromised system that could serve as a launch point for further attacks within the organizational network. Cybercriminals could leverage this foothold to propagate malware, disrupt services, or exfiltrate additional data across interconnected systems.
CISA has reported CVE-2026-82078
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-82078 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
PaperCut MF/NG 0 < 24.1.10
PaperCut MF/NG 25.0.0 < 25.0.13
PaperCut MF/NG 26.0.0 < 26.0.5
News Articles
Recently patched PaperCut zero-days used in data theft attacks
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.
3 weeks ago
PaperCut Exploitation Escalates to Active Intrusions
PaperCut attacks exploiting CVE-2026-82078 and CVE-2026-81578 have escalated, with hackers performing hands-on-keyboard activity.
3 weeks ago
CISA Warns of Multiple PaperCut NG/MF Vulnerabilities Actively Exploited in Attacks
CISA has added two vulnerabilities affecting PaperCut NG and PaperCut MF to its KEV Catalog, warning that threat actors are actively exploiting the flaws in real-world attacks.
3 weeks ago

References
CVSS V4
Timeline
- 👾
Exploit known to exist
- 🦅
CISA Reported
- 📰
First article discovered by Cybersecurity Dive
Vulnerability published
Vulnerability Reserved
