Unsafe reflection in PaperCut MF and PaperCut NG - CVE-2026-82078
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to use of externally-controlled input to select classes or code in the database connection utilities when instantiating database driver classes from configurable driver names. A remote privileged user can manipulate system configuration parameters to execute arbitrary code. The executed Java bytecode must already reside on the application classpath and runs under the security context of the PaperCut server process.
Note, the vulnerability is being exploited in the wild. In conjunction with #VU146038 (CVE-2026-81578) this vulnerability can be exploited by a remote non-authenticated attacker.
Affected software
PaperCut NG
How to mitigate CVE-2026-82078
PaperCut NG - addressed in versions 25.0.12, 26.0.4