CVE-2026-82077: PaperCut NG/MF: Remote Code Execution via Scan2Fax
Published Sep 24, 2026
·Updated
An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings.
Affected Software
2 affected components
PaperCut PaperCut NG
PaperCut PaperCut MF
Event History
Sep 24, 2026
CVE Published
via MITRE·06:43 AM
Data Sourced
via MITRE·06:43 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated administrator with access to the Scan-to-Fax component and the ability to supply crafted fax provider settings can exploit it.
2
What level of access does successful exploitation provide?
Successful exploitation allows arbitrary commands to be executed on the underlying host.
3
What configuration area should administrators review while assessing exposure?
Review Scan-to-Fax fax provider settings, particularly any settings that accept or construct file paths, because crafted values can trigger the path traversal and command execution condition.