CVE-2026-81578: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
Other sources
PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Evaluate each PaperCut MF/NG asset's internet exposure and ensure adherence to BOD 26-04 patching guidance; if the web management interface is internet-accessible, restrict access to trusted networks/hosts until the vendor mitigations/patches are applied.
Event History
Frequently Asked Questions
Does exploitation require valid PaperCut credentials or local access?
No. The issue can be triggered by unauthenticated remote requests targeting administrative functions in the web management interface.
Which installations should be considered potentially exposed?
PaperCut MF and PaperCut NG installations with the web management interface reachable by remote attackers should be considered potentially exposed. The specific conditions required for exploitation are not provided.