Missing authentication for critical function in PaperCut MF and PaperCut NG - CVE-2026-81578

 

Missing authentication for critical function in PaperCut MF and PaperCut NG - CVE-2026-81578

Published: August 28, 2026


Vulnerability identifier: #VU146038
CSH Severity: Critical
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-81578
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to modify certain system configurations.

The vulnerability exists due to missing authentication for critical function in the web management interface when handling unauthenticated remote requests targeting administrative functions before access validation checks complete. A remote attacker can send crafted requests to administrative functions to modify certain system configurations.

Note, the vulnerability is being actively exploited in the wild.


Affected software

PaperCut MF
PaperCut NG

How to mitigate CVE-2026-81578

Install security update from vendor's website.

PaperCut MF - addressed in versions 25.0.12, 26.0.4
PaperCut NG - addressed in versions 25.0.12, 26.0.4

External References

Related Security Bulletins