Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

CVE-2026-81578: PaperCut MF/NG web interface lets unauthenticated users change settings

CVE-2026-81578 · published 6 days ago · actively exploited
Summary

The web management console of PaperCut MF and PaperCut NG can be accessed without a login under certain conditions, allowing outsiders to alter system configurations. This could lead to unintended changes that affect printing policies or security settings. Apply the latest updates from PaperCut and limit access to the management console to trusted networks or users.

What to do
  • Update papercut papercut mf/ng to version 24.1.10, 25.0.13, 26.0.5 or later.
Affected software
VendorProductAffected versions
papercut ng/mf All versions
papercut papercut mf/ng < 24.1.10, 25.0.13, 26.0.5
papercut papercut_mf < 24.1.9
>= 25.0.2, < 25.0.12
>= 26.0.2, < 26.0.4
cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
papercut papercut_ng < 24.1.9
>= 25.0.2, < 25.0.12
>= 26.0.2, < 26.0.4
cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*
Original advisory text
PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.
Severity
8.8 High
CVSS 4.0: 8.8 (NVD)
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
EPSS <1%
Type
CWE-305Authentication Bypass by Primary Weakness
Timeline
Published28 Aug 2026
Updated2 Sep 2026
First seen28 Aug 2026
Sources
CVE-2026-81578 · MITRE
CVE-2026-81578 · CISA KEV
Monitor software like this
Free during beta