Missing authentication for critical function in PaperCut MF and PaperCut NG - CVE-2026-81578
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify certain system configurations.
The vulnerability exists due to missing authentication for critical function in the web management interface when handling unauthenticated remote requests targeting administrative functions before access validation checks complete. A remote attacker can send crafted requests to administrative functions to modify certain system configurations.
Note, the vulnerability is being actively exploited in the wild.
Affected software
PaperCut NG
How to mitigate CVE-2026-81578
PaperCut NG - addressed in versions 25.0.12, 26.0.4