Vulnerability Intelligence Report
PaperCut NG/MF: Remote Code Execution via Scan2Fax
CVE-2026-82077
An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings.
Injection
No Active Exploit Signals
CVSS Base Score
7.3
HIGH
EPSS Probability:0.74%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-22 ↗CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-78 ↗CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| PaperCut | PaperCut NG/MF | 0 < 25.0.13 (affected), 26.0.0 < 26.0.5 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | PaperCut Software Pty Ltd · Vendor · Australia |
| Reserved | 2026-08-28T00:13:21 |
| Published | 2026-09-24T06:43:35 |
| Last Updated | 2026-09-24T12:45:33 |
Community Chatter & Buzz