CVE-2026-14780: PaperCut NG/MF: Remote Code Execution via Scripting Subsystem
Published Sep 24, 2026
·Updated
A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine. An authenticated user with administrative access to the management interface can supply a malicious script that escapes the runtime sandbox.
A successful execution enables an attacker to run unauthorized operating system commands with administrative privileges on the host operating system.
Affected Software
1 affected component
PaperCut PaperCut NG/MF
Event History
Sep 24, 2026
CVE Published
via MITRE·05:17 AM
Data Sourced
via MITRE·05:17 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access is required to exploit this issue?
An attacker must be authenticated to the management interface and have administrative access.
2
What access could an attacker obtain after successful exploitation?
Successful exploitation allows unauthorized operating system commands to be executed with administrative privileges on the host.