PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector
Summary
| CVE | CVE-2026-82078 |
|---|---|
| State | PUBLISHED |
| Assigner | PaperCut |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-28 16:18:31 UTC |
| Updated | 2026-09-14 00:16:56 UTC |
| Description | An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. |
Risk And Classification
Primary CVSS: v4.0 9.4 CRITICAL from eb41dac7-0af8-4f84-9f6d-0272772514f4
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.035740000 probability, percentile 0.887840000 (date 2026-09-16)
CISA KEV: Listed on 2026-08-31; due 2026-09-14; ransomware use Unknown
Problem Types: CWE-470 | CWE-470 CWE-470 Use of Externally-Controlled input to select classes or code ('unsafe reflection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | eb41dac7-0af8-4f84-9f6d-0272772514f4 | Secondary | 9.4 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/C... |
| 4.0 | CNA | CVSS | 9.4 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
| 3.1 | [email protected] | Primary | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
HighUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
HighSub Conf.
HighSub Integrity
HighSub Availability
HighCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA Known Exploited Vulnerability
| Vendor | PaperCut |
|---|---|
| Product | NG/MF |
| Name | PaperCut NG/MF Unsafe Reflection Vulnerability |
| Required Action | Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. |
| Notes | https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/?lid=2oneu2wt0ct4 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-82078 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Papercut | Papercut Mf | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | PaperCut | PaperCut MF/NG | affected 24.1.10 semver | Not specified |
| CNA | PaperCut | PaperCut MF/NG | affected 25.0.0 25.0.13 semver | Not specified |
| CNA | PaperCut | PaperCut MF/NG | affected 26.0.0 26.0.5 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory | eb41dac7-0af8-4f84-9f6d-0272772514f4 | www.papercut.com | Patch, Vendor Advisory |
| github.com/rapid7/metasploit-framework/pull/21842 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | github.com | Issue Tracking, Patch |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | Patch, Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2026-08-28T00:00:00.000Z | CVE-2026-82078 added to CISA KEV |
There are currently no legacy QID mappings associated with this CVE.