Vulnerability

PaperCut NG/MF patched after two critical unauthenticated RCE flaws

⏱️ 4 min read📅 8/29/2026👁️ 15 views

Two critical PaperCut flaws spark emergency patches

PaperCut NG and PaperCut MF were hit with two high‑severity vulnerabilities – CVE‑2026‑81578 (improper access control, CVSS 8.8) and CVE‑2026‑82078 (unsafe dynamic class loading, CVSS 9.4) – and the vendor pushed back‑to‑back emergency patches.

What the bugs do

CVE‑2026‑81578 lets anyone send a remote request that reaches administrative functions before the product validates the caller’s rights. In practice that means an unauthenticated attacker can invoke actions that should be locked behind the admin UI.

CVE‑2026‑82078 drops the guardrail on Java’s class‑loading mechanism. The software loads database driver classes without an allow‑list, opening the door for arbitrary Java code to be executed on the server.

Early chatter on exploitation

Unconfirmed: Huntress researchers have said they observed limited exploitation in two customer environments, running Base64‑encoded commands such as “whoami & ver”. watchTowr has hinted that attackers may be chaining the two CVEs to bypass authentication and achieve remote code execution. These observations have not been independently verified.

Who needs to act

The flaws affect both PaperCut NG and PaperCut MF deployments – on‑premise servers that many schools, enterprises, and public institutions rely on for print management.

Defensive steps

  • Apply the first emergency patch released by PaperCut immediately, then follow up with the second hardening patch.
  • Block inbound traffic to the PaperCut management interface from untrusted networks; restrict access to known admin IP ranges.
  • Audit web server logs for unexpected calls to admin‑only endpoints, especially GET/POST requests that contain Base64 strings.
  • Monitor Java processes for the creation of unexpected .class files or files named “Udydn.out”, and watch for rapid log‑file deletions.
  • Enable multi‑factor authentication on the PaperCut admin console and enforce strong, unique passwords.

Even after patching, keep an eye on the environment for indicators of compromise that match the unverified reports.

#PaperCut#CVE-2026-81578#CVE-2026-82078#RCE#Patch#Java