Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
CVE-2026-81578: PaperCut MF/NG web interface lets unauthenticated users change settings
CVE-2026-81578 · published 6 days ago · actively exploited
Summary
The web management console of PaperCut MF and PaperCut NG can be accessed without a login under certain conditions, allowing outsiders to alter system configurations. This could lead to unintended changes that affect printing policies or security settings. Apply the latest updates from PaperCut and limit access to the management console to trusted networks or users.
What to do
- Update papercut papercut mf/ng to version 24.1.10, 25.0.13, 26.0.5 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| papercut | ng/mf | All versions |
| papercut | papercut mf/ng | < 24.1.10, 25.0.13, 26.0.5 |
| papercut | papercut_mf |
< 24.1.9 >= 25.0.2, < 25.0.12 >= 26.0.2, < 26.0.4 cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:* |
| papercut | papercut_ng |
< 24.1.9 >= 25.0.2, < 25.0.12 >= 26.0.2, < 26.0.4 cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:* |
Original advisory text
PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.
Severity
8.8
High
CVSS 4.0: 8.8 (NVD)
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
EPSS <1%
Type
CWE-305Authentication Bypass by Primary Weakness
Timeline
Published28 Aug 2026
Updated2 Sep 2026
First seen28 Aug 2026
Monitor software like this
Free during beta