ID:13037 - Exploit for Missing authentication for critical function in PaperCut MF and PaperCut NG - CVE-2026-81578
Published: September 3, 2026
PaperCut MF
PaperCut NG
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to modify certain system configurations.
The vulnerability exists due to missing authentication for critical function in the web management interface when handling unauthenticated remote requests targeting administrative functions before access validation checks complete. A remote attacker can send crafted requests to administrative functions to modify certain system configurations.
Note, the vulnerability is being actively exploited in the wild.