PaperCut MF/NG exploited, unauth config change (CVE-2026-81578) [PoC]
CVE-2026-81578
CVE-2026-81578: Actively exploited PaperCut MF/NG critical flaw lets unauthenticated attackers modify system config (CVSS 9.8). Update to latest version now.
Actively exploited in the wild - CVE-2026-81578 is a critical improper access control vulnerability in PaperCut MF and PaperCut NG that lets unauthenticated remote attackers modify system configurations through the web management interface. Patched in the latest MF/NG releases; update immediately.
Overview
CVE-2026-81578 stems from an access validation gap in the web management interface of PaperCut MF and PaperCut NG print management software. Under specific conditions, unauthenticated HTTP requests targeting administrative functions can trigger backend actions before authentication and authorization checks complete. This race condition lets attackers modify system configuration settings without valid credentials.
The vulnerability carries a CVSS score of 9.8 (Critical). The vector is network-based with low attack complexity, requires no privileges, and needs no user interaction, making it straightforward to exploit remotely.
CISA has confirmed active exploitation in the wild and added this CVE to its Known Exploited Vulnerabilities catalog. Despite a low EPSS score of 0.4% probability of exploitation in the next 30 days, the confirmed in-the-wild activity demands immediate attention.
Impact
An attacker exploiting CVE-2026-81578 can:
- Alter system configuration settings on the print server
- Potentially disable security controls or redirect print jobs
- Establish persistence for further attacks on the network
Because PaperCut often runs with elevated privileges on print servers, successful exploitation can also expose the broader network to lateral movement. Organizations running PaperCut in exposed or segmented environments should treat this as a network security incident, not just a print system issue.
Remediation
PaperCut has released patches for both MF and NG product lines. Take these steps:
-
Update immediately - Apply the latest PaperCut MF and NG versions from the vendor’s official download portal. Check the vendor advisory for version-specific patch details.
-
Restrict network access - Limit access to the web management interface to trusted administrative networks via firewall rules or VLAN segmentation.
-
Audit configurations - Review recent configuration changes on PaperCut servers for signs of unauthorized modification, especially if the server was internet-facing.
-
Monitor for indicators - Review access logs for suspicious requests targeting administrative endpoints from unexpected source IPs.
Security Insight
PaperCut joins a growing list of enterprise management platforms where authentication bypass flaws become the vector of choice for initial access. The pattern mirrors the 2023 PaperCut MF/NG RCE vulnerability (CVE-2023-27350), which was also actively exploited for ransomware deployment. That incident demonstrated that print management servers are not peripheral devices but high-value targets sitting on the network’s edge. The recurring theme is clear: vendors must treat access validation as a security boundary, not an optimization opportunity, and organizations must prioritize patching management interfaces alongside edge firewalls. More details on related incidents are available at security news and breach reports.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Public PoC References
Unverified third-party code
These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).
Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.
| Repository | Stars |
|---|---|
| yora1928/PaperCut-CVE-2026-81578-82078 Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078 | ★ 1 |
| virologi-info/papercut-toolkit #PaperCut CVE-2026-81578 + CVE-2026-82078 Defense Toolkit 2 3 A **defensive** toolkit to check and understand exposure to the chained | ★ 1 |
Showing 2 of 2 known references. Source: nomi-sec/PoC-in-GitHub.
Related Advisories
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable dri...
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The spe...
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation....
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network....
Other Papercut Mf Vulnerabilities
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable dri...
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The spe...