ID:13036 - Exploit for Unsafe reflection in PaperCut MF and PaperCut NG - CVE-2026-82078
Published: September 3, 2026
PaperCut MF
PaperCut NG
Link to public exploit:
Vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to use of externally-controlled input to select classes or code in the database connection utilities when instantiating database driver classes from configurable driver names. A remote privileged user can manipulate system configuration parameters to execute arbitrary code. The executed Java bytecode must already reside on the application classpath and runs under the security context of the PaperCut server process.
Note, the vulnerability is being exploited in the wild. In conjunction with #VU146038 (CVE-2026-81578) this vulnerability can be exploited by a remote non-authenticated attacker.