AI description
CVE-2026-82078 identifies an unsafe dynamic class-loading vulnerability present in the database connection utilities of PaperCut MF and PaperCut NG. This flaw allows the application to instantiate database driver classes using configurable driver names without proper validation against an approved allowlist of drivers. When exploited, particularly in conjunction with CVE-2026-81578 (an improper access control vulnerability), this vulnerability can enable an unauthenticated attacker to execute arbitrary Java bytecode. This chain of vulnerabilities ultimately facilitates pre-authentication remote code execution within the PaperCut Application Server.
- Description
- An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.
- Source
- eb41dac7-0af8-4f84-9f6d-0272772514f4
- NVD status
- Received
CVSS 4.0
- Type
- Secondary
- Base score
- 9.4
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- eb41dac7-0af8-4f84-9f6d-0272772514f4
- CWE-470
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
16
PaperCut says flaws in NG and MF, tracked as CVE-2026-82078 and CVE-2026-81578, are being actively exploited in customer incidents. Emergency patches are out after the first fix fell short. #PaperCut #CVE202682078 #CVE202681578 https://t.co/cRTW5JaXb1
@TweetThreatNews
29 Aug 2026
116 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
π¨ PaperCut NG/MF β RCE attacks are active CVE-2026-81578 + CVE-2026-82078 can be chained for unauthenticated RCE. PaperCut has released Emergency Patch Release 2. https://t.co/3tHQBoaIgE #CVE #PaperCut #RCE #CyberSecurity #InfoSec https://t.co/52JvtMEhLE
@stem__shop
29 Aug 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers chained two PaperCut zero-days to bypass authentication and execute arbitrary Java bytecode on print management servers. CVE-2026-82078 and CVE-2026-81578 enabled lateral movement through print infrastructure to broader network segments. Runtime segmentation helps
@aviatrixtrc
29 Aug 2026
24 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers chained CVE-2026-81578 and CVE-2026-82078 to achieve unauthenticated RCE on PaperCut print management systems. TRC analysis shows threat actors deployed Java payloads for system reconnaissance before cleaning up evidence. Print infrastructure compromises can enable
@aviatrixtrc
28 Aug 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Been burning the midnight oil a lot this week to chase things -- latest escapade has been digging into PaperCut CVE-2026-81578 and CVE-2026-82078, pre-auth RCE.. The useful takeaway is in the implementation tradeoff, not the announcement.
@ZeroDayDevApp
28 Aug 2026
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers are chaining two @PaperCutDev NG/MF flaws for unauthenticated RCE. CVE-2026-81578 (8.8): auth bypass on the admin web UI CVE-2026-82078 (9.4): unsafe Java class loading β code execution @HuntressLabs has seen limited in-the-wild use. Take PaperCut off the public
@LinuxTuts123
28 Aug 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Been burning the midnight oil a lot this week to chase things -- latest escapade has been digging into PaperCut CVE-2026-81578 and CVE-2026-82078, pre-auth RCE. I recreated a PoC, coordinated with PaperCut, and we saw in-the-wild exploitation. More soon. https://t.co/aBN3Rmy4s4
@_JohnHammond
28 Aug 2026
7955 Impressions
14 Retweets
78 Likes
20 Bookmarks
5 Replies
1 Quote
Attackers are chaining two @PaperCutDev NG/MF flaws for unauthenticated RCE. CVE-2026-81578 (8.8): auth bypass on the admin web UI CVE-2026-82078 (9.4): unsafe Java class loading β code execution @HuntressLabs has seen limited in-the-wild use. Take PaperCut off the public
@LinuxTuts123
28 Aug 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers are chaining two @PaperCutDev NG/MF flaws for unauthenticated RCE. CVE-2026-81578 (8.8): auth bypass on the admin web UI CVE-2026-82078 (9.4): unsafe Java class loading β code execution @HuntressLabs has seen limited in-the-wild use. Install Emergency Patch Release
@LinuxTuts123
28 Aug 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers are chaining two @PaperCutDev NG/MF flaws for unauthenticated RCE. CVE-2026-81578 (8.8): auth bypass on the admin web UI CVE-2026-82078 (9.4): unsafe Java class loading β code execution @HuntressLabs has seen limited in-the-wild use. Patch Emergency Release 2 and tak
@LinuxTuts123
28 Aug 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Warning: Critical and High vulnerability in #PaperCut. #CVE-2026-82078 #CVE-2026-81578 CVSS: 9.4 CVSS: 8.8. These vulnerabilities combined can lead to full system compromise #RCE! Read our advisory: https://t.co/BbqnY4Qezp and #Patch #Patch #Patch
@CCBalert
28 Aug 2026
259 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PaperCut NG/MF is under active exploitation. Attack path: Internet exposure β CVE-2026-81578 auth bypass β config change β CVE-2026-82078 β server-side Java execution. Vufay validates whether the full path is actually reachable. #CVE202681578 #CVE202682078 https://t.c
@vufaysecurity
28 Aug 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
π¨ On 8/27/26, #PaperCut Software published an urgent security advisory, detailing active exploitation of a vuln affecting PaperCut NG & MF. PaperCut has confirmed customer incidents. More on CVE-2026-81578 and CVE-2026-82078 in our blog: https://t.co/EOWF2xVxjl https://t.
@rapid7
28 Aug 2026
2180 Impressions
1 Retweet
4 Likes
2 Bookmarks
0 Replies
0 Quotes
π¨π¨π¨ γPaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF.γ CVE-2026-82078 CVE-2026-81578 URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) https://t.co/inq8p8sd
@autumn_good_35
28 Aug 2026
762 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
1 Quote