Vulnerability Description
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Papercut | Papercut Mf | < 24.1.9 |
| Papercut | Papercut Ng | < 24.1.9 |
Related Weaknesses (CWE)
References
- https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-aPatchVendor Advisory
- https://github.com/rapid7/metasploit-framework/pull/21842Issue TrackingPatch
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-PatchThird Party AdvisoryUS Government Resource
FAQ
What is CVE-2026-81578?
CVE-2026-81578 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative func...
How severe is CVE-2026-81578?
CVE-2026-81578 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-81578?
Check the references section above for vendor advisories and patch information. Affected products include: Papercut Papercut Mf, Papercut Papercut Ng.