8 min read
By: RedLegg's Cyber Threat Intelligence Team
About:
CVE-2026-82078 and CVE-2026-81578 are critical and high-severity vulnerabilities affecting PaperCut NG and PaperCut MF.
CVE-2026-82078 is an unsafe dynamic class loading vulnerability that may allow an attacker who can manipulate system configuration parameters to execute arbitrary Java bytecode under the security context of the PaperCut server process.
CVE-2026-81578 is an improper access control vulnerability that may allow an unauthenticated remote attacker to trigger administrative backend actions before access validation is completed, potentially enabling unauthorized modification of system configurations.
PaperCut has confirmed customer incidents involving active exploitation. The vendor has released Emergency Patch Release 2 and recommends that all customers install it, including those that previously applied the original emergency patch.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
VULNERABILITIES
Unsafe Dynamic Class Loading and Authentication Bypass in PaperCut NG and PaperCut MF
Identifier: CVE-2026-82078, CVE-2026-81578
PoC or Exploitation: Confirmed actively exploited in the wild. PaperCut states it is aware of confirmed customer incidents.
CVSS Score: 9.4, Critical, CVSS v4.0 for CVE-2026-82078 . 8.8, High, CVSS v4.0 for CVE-2026-81578
Update / Patch:
- All versions of PaperCut NG
- All versions of PaperCut MF
Description:
CVE-2026-81578 is an improper access control vulnerability in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions before access validation checks complete. This allows an unauthenticated remote attacker to modify certain system configurations.
Mitigation Recommendation: