>samit_hota
Back to advisories

Security Advisory · SH-2026-160

CRITICALCVE-2026-81578CVSS 9.8OPEN

PaperCut NG/MF Critical Vulnerability CVE-2026-81578 Exposes Systems to Takeover

Affected: PaperCut NG/MF

Samit Hota·
#kev#papercut

Unauthenticated remote attackers can alter critical system configurations in vulnerable installations of PaperCut print management software. Tracked as CVE-2026-81578, this high-severity PaperCut NG/MF vulnerability stems from missing authentication on sensitive internal management endpoints. Because print management servers typically operate with elevated privileges—frequently NT AUTHORITY\SYSTEM on Windows or root on Linux—unauthenticated control over application settings opens a direct line to full system compromise.

The PaperCut NG/MF Vulnerability (CVE-2026-81578) Explained

The flaw is classified under CWE-305 (Surrender of Control in Missing Authentication). Certain management routines within the web application fail to enforce session authorization checks, allowing external HTTP requests to modify underlying application configurations directly.

While the measured EPSS score sits at 0.39% (32.4th percentile), this lower probability figure is typical for newly published CVEs prior to widespread automated exploitation scans hitting public telemetry. The underlying metric that matters for defensive posture is the maximum CVSS v3.1 score of 9.8 with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The attack is fully remote, low complexity, requires zero privileges, and demands no user interaction.

Exploit Chaining and Threat Mechanics

In enterprise environments, PaperCut is rarely a standalone application; it interfaces closely with domain controllers, active directory sync services, and local print spoolers. By manipulating configuration settings via CVE-2026-81578, an attacker can rebind administrative settings, alter server-side scripts, or reconfigure user sync settings.

Crucially, this flaw is designed to be chained with CVE-2026-82078. Exploit development against print infrastructure commonly uses a two-stage pattern: an initial missing authentication bug alters configuration states or enables administrative features, which then allows a second vulnerability to achieve arbitrary command execution or file overwrite primitives. Public exploit code submissions to frameworks like Metasploit highlight that functional exploit chains are already actively being developed and tested.

Exposed Environments and Risk Profile

PaperCut NG and MF are ubiquitous in higher education, healthcare, legal, and government sectors, where multi-tenant print tracking and badge-release workflows are required. Web management ports 9191 (HTTP) and 9192 (HTTPS) are frequently exposed across internal network segments and, in misconfigured environments, directly to the public internet.

Threat actors routinely scan for exposed print servers because compromising them provides immediate access to domain service accounts, printer memory caches, user directory databases, and a privileged foothold on the host operating system for lateral movement.

Specific Patch and Remediation Requirements

Administrators operating affected versions must apply updates immediately to close the missing authentication flaw. The vendor has released updates across active release branches:

  • 24.x instances: Upgrade to 24.1.9 or later.
  • 25.x instances: Upgrade to 25.0.12 or later.
  • 26.x instances: Upgrade to 26.0.4 or later.

Organizations working under federal compliance standards must adhere to CISA BOD 26-04 mitigation timelines with a compliance deadline of September 14, 2026. If immediate patching is not possible, isolate management interfaces by restricting incoming traffic on TCP ports 9191 and 9192 at network firewalls so that only authorized administrative subnets can reach the server. Additionally, review application audit logs for unauthorized configuration modifications or unexpected administrator account additions prior to applying the patch.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call