Unsafe reflection in PaperCut MF and PaperCut NG - CVE-2026-82078

 

Unsafe reflection in PaperCut MF and PaperCut NG - CVE-2026-82078

Published: August 28, 2026


Vulnerability identifier: #VU146037
CSH Severity: Critical
CVSS v4: 10 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2026-82078
CWE-ID: CWE-470
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to use of externally-controlled input to select classes or code in the database connection utilities when instantiating database driver classes from configurable driver names. A remote privileged user can manipulate system configuration parameters to execute arbitrary code. The executed Java bytecode must already reside on the application classpath and runs under the security context of the PaperCut server process.

Note, the vulnerability is being exploited in the wild. In conjunction with #VU146038 (CVE-2026-81578) this vulnerability can be exploited by a remote non-authenticated attacker. 


Affected software

PaperCut MF
PaperCut NG

How to mitigate CVE-2026-82078

Install security update from vendor's website.

PaperCut MF - addressed in versions 25.0.12, 26.0.4
PaperCut NG - addressed in versions 25.0.12, 26.0.4

External References

Related Security Bulletins