CVE-2026-81578

Published Aug 28, 2026

Last updated 9 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-81578 describes an improper access control vulnerability found in the web management interface of PaperCut MF and PaperCut NG. This flaw allows unauthenticated remote requests, specifically those targeting administrative functions, to initiate backend actions before the system fully completes its access validation checks. The vulnerability, categorized as CWE-306 (Missing authentication for critical function), enables an unauthenticated remote attacker to modify certain system configurations. It has been observed to be actively exploited in the wild, often in conjunction with CVE-2026-82078, to achieve broader compromise.

Description
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
Source
eb41dac7-0af8-4f84-9f6d-0272772514f4
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.8
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

Weaknesses

eb41dac7-0af8-4f84-9f6d-0272772514f4
CWE-305

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

16

  1. PaperCut says flaws in NG and MF, tracked as CVE-2026-82078 and CVE-2026-81578, are being actively exploited in customer incidents. Emergency patches are out after the first fix fell short. #PaperCut #CVE202682078 #CVE202681578 https://t.co/cRTW5JaXb1

    @TweetThreatNews

    29 Aug 2026

    116 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 PaperCut NG/MF — RCE attacks are active CVE-2026-81578 + CVE-2026-82078 can be chained for unauthenticated RCE. PaperCut has released Emergency Patch Release 2. https://t.co/3tHQBoaIgE #CVE #PaperCut #RCE #CyberSecurity #InfoSec https://t.co/52JvtMEhLE

    @stem__shop

    29 Aug 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Attackers chained two PaperCut zero-days to bypass authentication and execute arbitrary Java bytecode on print management servers. CVE-2026-82078 and CVE-2026-81578 enabled lateral movement through print infrastructure to broader network segments. Runtime segmentation helps

    @aviatrixtrc

    29 Aug 2026

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Attackers chained CVE-2026-81578 and CVE-2026-82078 to achieve unauthenticated RCE on PaperCut print management systems. TRC analysis shows threat actors deployed Java payloads for system reconnaissance before cleaning up evidence. Print infrastructure compromises can enable

    @aviatrixtrc

    28 Aug 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Been burning the midnight oil a lot this week to chase things -- latest escapade has been digging into PaperCut CVE-2026-81578 and CVE-2026-82078, pre-auth RCE.. The useful takeaway is in the implementation tradeoff, not the announcement.

    @ZeroDayDevApp

    28 Aug 2026

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Attackers are chaining two @PaperCutDev NG/MF flaws for unauthenticated RCE. CVE-2026-81578 (8.8): auth bypass on the admin web UI CVE-2026-82078 (9.4): unsafe Java class loading → code execution @HuntressLabs has seen limited in-the-wild use. Take PaperCut off the public

    @LinuxTuts123

    28 Aug 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Been burning the midnight oil a lot this week to chase things -- latest escapade has been digging into PaperCut CVE-2026-81578 and CVE-2026-82078, pre-auth RCE. I recreated a PoC, coordinated with PaperCut, and we saw in-the-wild exploitation. More soon. https://t.co/aBN3Rmy4s4

    @_JohnHammond

    28 Aug 2026

    7955 Impressions

    14 Retweets

    78 Likes

    20 Bookmarks

    5 Replies

    1 Quote

  8. Attackers are chaining two @PaperCutDev NG/MF flaws for unauthenticated RCE. CVE-2026-81578 (8.8): auth bypass on the admin web UI CVE-2026-82078 (9.4): unsafe Java class loading → code execution @HuntressLabs has seen limited in-the-wild use. Take PaperCut off the public

    @LinuxTuts123

    28 Aug 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Attackers are chaining two @PaperCutDev NG/MF flaws for unauthenticated RCE. CVE-2026-81578 (8.8): auth bypass on the admin web UI CVE-2026-82078 (9.4): unsafe Java class loading → code execution @HuntressLabs has seen limited in-the-wild use. Install Emergency Patch Release

    @LinuxTuts123

    28 Aug 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Attackers are chaining two @PaperCutDev NG/MF flaws for unauthenticated RCE. CVE-2026-81578 (8.8): auth bypass on the admin web UI CVE-2026-82078 (9.4): unsafe Java class loading → code execution @HuntressLabs has seen limited in-the-wild use. Patch Emergency Release 2 and tak

    @LinuxTuts123

    28 Aug 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Warning: Critical and High vulnerability in #PaperCut. #CVE-2026-82078 #CVE-2026-81578 CVSS: 9.4 CVSS: 8.8. These vulnerabilities combined can lead to full system compromise #RCE! Read our advisory: https://t.co/BbqnY4Qezp and #Patch #Patch #Patch

    @CCBalert

    28 Aug 2026

    259 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. PaperCut NG/MF is under active exploitation. Attack path: Internet exposure → CVE-2026-81578 auth bypass → config change → CVE-2026-82078 → server-side Java execution. Vufay validates whether the full path is actually reachable. #CVE202681578 #CVE202682078 https://t.c

    @vufaysecurity

    28 Aug 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🚨 On 8/27/26, #PaperCut Software published an urgent security advisory, detailing active exploitation of a vuln affecting PaperCut NG & MF. PaperCut has confirmed customer incidents. More on CVE-2026-81578 and CVE-2026-82078 in our blog: https://t.co/EOWF2xVxjl https://t.

    @rapid7

    28 Aug 2026

    2180 Impressions

    1 Retweet

    4 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  14. 🚨🚨🚨 『PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF.』 CVE-2026-82078 CVE-2026-81578 URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) https://t.co/inq8p8sd

    @autumn_good_35

    28 Aug 2026

    762 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    1 Quote