AI description
CVE-2026-81578 describes an improper access control vulnerability found in the web management interface of PaperCut MF and PaperCut NG. This flaw allows unauthenticated remote requests, specifically those targeting administrative functions, to initiate backend actions before the system fully completes its access validation checks. The vulnerability, categorized as CWE-306 (Missing authentication for critical function), enables an unauthenticated remote attacker to modify certain system configurations. It has been observed to be actively exploited in the wild, often in conjunction with CVE-2026-82078, to achieve broader compromise.
- Description
- An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
- Source
- eb41dac7-0af8-4f84-9f6d-0272772514f4
- NVD status
- Received
CVSS 4.0
- Type
- Secondary
- Base score
- 8.8
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
- eb41dac7-0af8-4f84-9f6d-0272772514f4
- CWE-305
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
16
PaperCut says flaws in NG and MF, tracked as CVE-2026-82078 and CVE-2026-81578, are being actively exploited in customer incidents. Emergency patches are out after the first fix fell short. #PaperCut #CVE202682078 #CVE202681578 https://t.co/cRTW5JaXb1
@TweetThreatNews
29 Aug 2026
116 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 PaperCut NG/MF — RCE attacks are active CVE-2026-81578 + CVE-2026-82078 can be chained for unauthenticated RCE. PaperCut has released Emergency Patch Release 2. https://t.co/3tHQBoaIgE #CVE #PaperCut #RCE #CyberSecurity #InfoSec https://t.co/52JvtMEhLE
@stem__shop
29 Aug 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers chained two PaperCut zero-days to bypass authentication and execute arbitrary Java bytecode on print management servers. CVE-2026-82078 and CVE-2026-81578 enabled lateral movement through print infrastructure to broader network segments. Runtime segmentation helps
@aviatrixtrc
29 Aug 2026
24 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers chained CVE-2026-81578 and CVE-2026-82078 to achieve unauthenticated RCE on PaperCut print management systems. TRC analysis shows threat actors deployed Java payloads for system reconnaissance before cleaning up evidence. Print infrastructure compromises can enable
@aviatrixtrc
28 Aug 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Been burning the midnight oil a lot this week to chase things -- latest escapade has been digging into PaperCut CVE-2026-81578 and CVE-2026-82078, pre-auth RCE.. The useful takeaway is in the implementation tradeoff, not the announcement.
@ZeroDayDevApp
28 Aug 2026
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers are chaining two @PaperCutDev NG/MF flaws for unauthenticated RCE. CVE-2026-81578 (8.8): auth bypass on the admin web UI CVE-2026-82078 (9.4): unsafe Java class loading → code execution @HuntressLabs has seen limited in-the-wild use. Take PaperCut off the public
@LinuxTuts123
28 Aug 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Been burning the midnight oil a lot this week to chase things -- latest escapade has been digging into PaperCut CVE-2026-81578 and CVE-2026-82078, pre-auth RCE. I recreated a PoC, coordinated with PaperCut, and we saw in-the-wild exploitation. More soon. https://t.co/aBN3Rmy4s4
@_JohnHammond
28 Aug 2026
7955 Impressions
14 Retweets
78 Likes
20 Bookmarks
5 Replies
1 Quote
Attackers are chaining two @PaperCutDev NG/MF flaws for unauthenticated RCE. CVE-2026-81578 (8.8): auth bypass on the admin web UI CVE-2026-82078 (9.4): unsafe Java class loading → code execution @HuntressLabs has seen limited in-the-wild use. Take PaperCut off the public
@LinuxTuts123
28 Aug 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers are chaining two @PaperCutDev NG/MF flaws for unauthenticated RCE. CVE-2026-81578 (8.8): auth bypass on the admin web UI CVE-2026-82078 (9.4): unsafe Java class loading → code execution @HuntressLabs has seen limited in-the-wild use. Install Emergency Patch Release
@LinuxTuts123
28 Aug 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers are chaining two @PaperCutDev NG/MF flaws for unauthenticated RCE. CVE-2026-81578 (8.8): auth bypass on the admin web UI CVE-2026-82078 (9.4): unsafe Java class loading → code execution @HuntressLabs has seen limited in-the-wild use. Patch Emergency Release 2 and tak
@LinuxTuts123
28 Aug 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Warning: Critical and High vulnerability in #PaperCut. #CVE-2026-82078 #CVE-2026-81578 CVSS: 9.4 CVSS: 8.8. These vulnerabilities combined can lead to full system compromise #RCE! Read our advisory: https://t.co/BbqnY4Qezp and #Patch #Patch #Patch
@CCBalert
28 Aug 2026
259 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PaperCut NG/MF is under active exploitation. Attack path: Internet exposure → CVE-2026-81578 auth bypass → config change → CVE-2026-82078 → server-side Java execution. Vufay validates whether the full path is actually reachable. #CVE202681578 #CVE202682078 https://t.c
@vufaysecurity
28 Aug 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 On 8/27/26, #PaperCut Software published an urgent security advisory, detailing active exploitation of a vuln affecting PaperCut NG & MF. PaperCut has confirmed customer incidents. More on CVE-2026-81578 and CVE-2026-82078 in our blog: https://t.co/EOWF2xVxjl https://t.
@rapid7
28 Aug 2026
2180 Impressions
1 Retweet
4 Likes
2 Bookmarks
0 Replies
0 Quotes
🚨🚨🚨 『PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF.』 CVE-2026-82078 CVE-2026-81578 URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) https://t.co/inq8p8sd
@autumn_good_35
28 Aug 2026
762 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
1 Quote