ID:13036 - Exploit for Unsafe reflection in PaperCut MF and PaperCut NG - CVE-2026-82078

 
Main Vulnerability Database Exploits ID:13036 - Exploit for Unsafe reflection in PaperCut MF and PaperCut NG - CVE-2026-82078

ID:13036 - Exploit for Unsafe reflection in PaperCut MF and PaperCut NG - CVE-2026-82078

Published: September 3, 2026


Vulnerability identifier: #VU146037
Vulnerability risk: Critical
CVE-ID: CVE-2026-82078
CWE-ID: CWE-470
Exploitation vector: Remote access
Vulnerable software:
PaperCut MF
PaperCut NG

Link to public exploit:


Vulnerability description

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to use of externally-controlled input to select classes or code in the database connection utilities when instantiating database driver classes from configurable driver names. A remote privileged user can manipulate system configuration parameters to execute arbitrary code. The executed Java bytecode must already reside on the application classpath and runs under the security context of the PaperCut server process.

Note, the vulnerability is being exploited in the wild. In conjunction with #VU146038 (CVE-2026-81578) this vulnerability can be exploited by a remote non-authenticated attacker. 


Remediation

Install security update from vendor's website.