CVE-2026-82078

Published Aug 28, 2026

Last updated 9 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-82078 identifies an unsafe dynamic class-loading vulnerability present in the database connection utilities of PaperCut MF and PaperCut NG. This flaw allows the application to instantiate database driver classes using configurable driver names without proper validation against an approved allowlist of drivers. When exploited, particularly in conjunction with CVE-2026-81578 (an improper access control vulnerability), this vulnerability can enable an unauthenticated attacker to execute arbitrary Java bytecode. This chain of vulnerabilities ultimately facilitates pre-authentication remote code execution within the PaperCut Application Server.

Description
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.
Source
eb41dac7-0af8-4f84-9f6d-0272772514f4
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.4
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

eb41dac7-0af8-4f84-9f6d-0272772514f4
CWE-470

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

16

  1. PaperCut says flaws in NG and MF, tracked as CVE-2026-82078 and CVE-2026-81578, are being actively exploited in customer incidents. Emergency patches are out after the first fix fell short. #PaperCut #CVE202682078 #CVE202681578 https://t.co/cRTW5JaXb1

    @TweetThreatNews

    29 Aug 2026

    116 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 PaperCut NG/MF β€” RCE attacks are active CVE-2026-81578 + CVE-2026-82078 can be chained for unauthenticated RCE. PaperCut has released Emergency Patch Release 2. https://t.co/3tHQBoaIgE #CVE #PaperCut #RCE #CyberSecurity #InfoSec https://t.co/52JvtMEhLE

    @stem__shop

    29 Aug 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Attackers chained two PaperCut zero-days to bypass authentication and execute arbitrary Java bytecode on print management servers. CVE-2026-82078 and CVE-2026-81578 enabled lateral movement through print infrastructure to broader network segments. Runtime segmentation helps

    @aviatrixtrc

    29 Aug 2026

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Attackers chained CVE-2026-81578 and CVE-2026-82078 to achieve unauthenticated RCE on PaperCut print management systems. TRC analysis shows threat actors deployed Java payloads for system reconnaissance before cleaning up evidence. Print infrastructure compromises can enable

    @aviatrixtrc

    28 Aug 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Been burning the midnight oil a lot this week to chase things -- latest escapade has been digging into PaperCut CVE-2026-81578 and CVE-2026-82078, pre-auth RCE.. The useful takeaway is in the implementation tradeoff, not the announcement.

    @ZeroDayDevApp

    28 Aug 2026

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Attackers are chaining two @PaperCutDev NG/MF flaws for unauthenticated RCE. CVE-2026-81578 (8.8): auth bypass on the admin web UI CVE-2026-82078 (9.4): unsafe Java class loading β†’ code execution @HuntressLabs has seen limited in-the-wild use. Take PaperCut off the public

    @LinuxTuts123

    28 Aug 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Been burning the midnight oil a lot this week to chase things -- latest escapade has been digging into PaperCut CVE-2026-81578 and CVE-2026-82078, pre-auth RCE. I recreated a PoC, coordinated with PaperCut, and we saw in-the-wild exploitation. More soon. https://t.co/aBN3Rmy4s4

    @_JohnHammond

    28 Aug 2026

    7955 Impressions

    14 Retweets

    78 Likes

    20 Bookmarks

    5 Replies

    1 Quote

  8. Attackers are chaining two @PaperCutDev NG/MF flaws for unauthenticated RCE. CVE-2026-81578 (8.8): auth bypass on the admin web UI CVE-2026-82078 (9.4): unsafe Java class loading β†’ code execution @HuntressLabs has seen limited in-the-wild use. Take PaperCut off the public

    @LinuxTuts123

    28 Aug 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Attackers are chaining two @PaperCutDev NG/MF flaws for unauthenticated RCE. CVE-2026-81578 (8.8): auth bypass on the admin web UI CVE-2026-82078 (9.4): unsafe Java class loading β†’ code execution @HuntressLabs has seen limited in-the-wild use. Install Emergency Patch Release

    @LinuxTuts123

    28 Aug 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Attackers are chaining two @PaperCutDev NG/MF flaws for unauthenticated RCE. CVE-2026-81578 (8.8): auth bypass on the admin web UI CVE-2026-82078 (9.4): unsafe Java class loading β†’ code execution @HuntressLabs has seen limited in-the-wild use. Patch Emergency Release 2 and tak

    @LinuxTuts123

    28 Aug 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Warning: Critical and High vulnerability in #PaperCut. #CVE-2026-82078 #CVE-2026-81578 CVSS: 9.4 CVSS: 8.8. These vulnerabilities combined can lead to full system compromise #RCE! Read our advisory: https://t.co/BbqnY4Qezp and #Patch #Patch #Patch

    @CCBalert

    28 Aug 2026

    259 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. PaperCut NG/MF is under active exploitation. Attack path: Internet exposure β†’ CVE-2026-81578 auth bypass β†’ config change β†’ CVE-2026-82078 β†’ server-side Java execution. Vufay validates whether the full path is actually reachable. #CVE202681578 #CVE202682078 https://t.c

    @vufaysecurity

    28 Aug 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🚨 On 8/27/26, #PaperCut Software published an urgent security advisory, detailing active exploitation of a vuln affecting PaperCut NG & MF. PaperCut has confirmed customer incidents. More on CVE-2026-81578 and CVE-2026-82078 in our blog: https://t.co/EOWF2xVxjl https://t.

    @rapid7

    28 Aug 2026

    2180 Impressions

    1 Retweet

    4 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  14. 🚨🚨🚨 γ€ŽPaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF.』 CVE-2026-82078 CVE-2026-81578 URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) https://t.co/inq8p8sd

    @autumn_good_35

    28 Aug 2026

    762 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    1 Quote