CVE-2026-87739: PaperCut MF/NG: User permissions are not evaluated on report generation
Published Sep 24, 2026
·Updated
An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and gain unauthorized access to sensitive information.
Affected Software
1 affected component
PaperCut PaperCut MF/NG
Event History
Sep 24, 2026
CVE Published
via MITRE·06:46 AM
Data Sourced
via MITRE·06:46 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated remote attacker can exploit it by submitting report-generation requests without valid credentials.
2
What could an attacker obtain through exploitation?
The attacker can trigger report generation and gain unauthorized access to sensitive information contained in generated reports.