Back

HIGH

PaperCut NG/MF: Remote Code Execution via Scripting Subsystem

Published Sep 24, 2026

Description

A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine. An authenticated user with administrative access to the management interface can supply a malicious script that escapes the runtime sandbox.

A successful execution enables an attacker to run unauthorized operating system commands with administrative privileges on the host operating system.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner PaperCut
Published Sep 24, 2026
Updated Sep 25, 2026
Reserved Jul 5, 2026

CISA Vulnrichment

Updated Sep 24, 2026

NVD

Status Received
Modified Sep 24, 2026

Red Hat

No data

ENISA EUVD

Assigner PaperCut
Published Sep 24, 2026
Updated Sep 25, 2026

GitHub

No data