CVE-2023-27350

Published Apr 20, 2023

Last updated 3 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2023-27350 is an unauthenticated remote code execution vulnerability affecting PaperCut MF and NG print management software. This flaw allows an attacker to bypass authentication and execute arbitrary code with SYSTEM privileges on vulnerable systems. The vulnerability is attributed to improper access controls within the `SetupCompleted` Java class. This issue impacts PaperCut MF or NG versions 8.0 and later, specifically including versions 8.0.0 to 19.2.7, 20.0.0 to 20.1.6, 21.0.0 to 21.2.10, and 22.0.0 to 22.0.8.

Description
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.
Source
zdi-disclosures@trendmicro.com
NVD status
Analyzed
Products
papercut_mf, papercut_ng

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

CVSS 3.0

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
PaperCut MF/NG Improper Access Control Vulnerability
Exploit added on
Apr 21, 2023
Exploit action due
May 12, 2023
Required action
Apply updates per vendor instructions.

Weaknesses

zdi-disclosures@trendmicro.com
CWE-284
nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending
  1. Bamboo from @hackthebox_eu and @vulnlab_eu features Squid proxy enumeration, CVE-2023-27350 authentication bypass to RCE in PaperCut NG, and binary hijacking of a root-executed script for privilege escalation. https://t.co/X31b7j3jOs

    @0xdf_

    3 Feb 2026

    2467 Impressions

    12 Retweets

    53 Likes

    19 Bookmarks

    1 Reply

    0 Quotes

  2. I just completed PaperCut: CVE-2023-27350 room on TryHackMe. Authorisation bypass (CVE-2023-27350) in PaperCut Print Management software leading to remote code execution. https://t.co/MP5quE0tbv #tryhackme via @tryhackme

    @JayeshV88153533

    27 Jan 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. I just completed PaperCut: CVE-2023-27350 room on TryHackMe. Authorisation bypass (CVE-2023-27350) in PaperCut Print Management software leading to remote code execution. https://t.co/IG21ynFJWp #tryhackme через @tryhackme

    @mrBr4un

    4 Jan 2026

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. I just completed PaperCut: CVE-2023-27350 room on TryHackMe. Authorisation bypass (CVE-2023-27350) in PaperCut Print Management software leading to remote code execution. https://t.co/LULF9vjdLP #tryhackme @tryhackmeより

    @yoshi_prog

    30 Oct 2025

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE ID : CVE-2023-27350 System : PaperCut NG 22.0.5 Type : bypass authentication CNA Score : 9.8 #Exploit PoC - https://t.co/m55Yub8nNF

    @ksg93rd

    15 Aug 2025

    129 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Threat Alert: BellaCiao: The .NET Malware with Advanced Sophisticated Threats - #APT35 CVE-2023-27350 CVE-2022-47966 CVE-2022-47986 Severity: 🔴 High Maturity: 💥 Mainstream Learn more: https://t.co/t7o0tVHbFA #CyberSecurity #ThreatIntel #InfoSec (1/3)

    @fletch_ai

    24 Dec 2024

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. Day 27 #100DaysofCyberSecurity Today I researched two vulnerabilities which are; 1. CVE-2023-27350 2. CVE-2023-23752 1. PaperCut (CVE-2023-27350) vulnerability, which allowed authorisation bypass in PaperCut Print Management software leading to remote code execution.

    @Nwaikwu_Bash

    27 Oct 2024

    43 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations