PaperCut MF/NG: Authentication Bypass
Summary
| CVE | CVE-2026-81578 |
|---|---|
| State | PUBLISHED |
| Assigner | PaperCut |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-28 16:18:29 UTC |
| Updated | 2026-08-28 20:20:11 UTC |
| Description | An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations. |
Risk And Classification
Primary CVSS: v4.0 8.8 HIGH from eb41dac7-0af8-4f84-9f6d-0272772514f4
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-305 | CWE-305 CWE-305 Authentication bypass by primary weakness
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | eb41dac7-0af8-4f84-9f6d-0272772514f4 | Secondary | 8.8 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 8.8 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
NoneUser Interaction
NoneConfidentiality
LowIntegrity
HighAvailability
LowSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | PaperCut | PaperCut MF/NG | affected 24.1.10, 25.0.13, 26.0.5 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory | eb41dac7-0af8-4f84-9f6d-0272772514f4 | www.papercut.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.