CVE-2026-81578KEV · due Sep 14CWE-305

PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

Critical · published August 28, 2026

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 9.8. It is confirmed in active exploitation. It sits in the 74.4th percentile for exploit probability.

7
days to CISA
deadline
CVSS v3.1
9.8
EPSS
2%
Percentile
74.4
In the wild
Confirmed
What it is

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
8.8 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
EPSS
0.01617 · 74.4th percentile
Weakness
CWE-305 · Authentication Bypass by Primary Weakness
Published
2026-08-28T20:18Z
KEV added
2026-08-31 · due 2026-09-14
Affected products (6)
ProductVersionsFixed in
papercut/papercut_mf< 24.1.924.1.9
papercut/papercut_mf≥ 25.0.2, < 25.0.1225.0.12
papercut/papercut_mf≥ 26.0.2, < 26.0.426.0.4
papercut/papercut_ng< 24.1.924.1.9
papercut/papercut_ng≥ 25.0.2, < 25.0.1225.0.12
papercut/papercut_ng≥ 26.0.2, < 26.0.426.0.4
References (3)
EPSS history
Timeline
  • 30 AUG 16:19Z
    EPSS moved — → 0%
    epss
  • 28 AUG 11:39Z
    PaperCut MF/NG: Authentication Bypass
    cvelistv5