Vulnerability Intelligence Report
PaperCut MF/NG: Authentication Bypass
CVE-2026-81578
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
8.8
HIGH
EPSS Probability:1.62%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-305 ↗CWE-305 Authentication bypass by primary weakness
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| PaperCut | PaperCut MF/NG | 0 < 24.1.10 (affected), 25.0.0 < 25.0.13 (affected), 26.0.0 < 26.0.5 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
1.617%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | PaperCut Software Pty Ltd · Vendor · Australia |
| Reserved | 2026-08-27T07:34:07 |
| Published | 2026-08-28T11:39:45 |
| Last Updated | 2026-09-13T23:15:33 |
Community Chatter & Buzz