Back

HIGH KEV

PaperCut MF/NG: Authentication Bypass

Published Aug 28, 2026 ·Due Sep 14, 2026

Description

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner PaperCut
Published Aug 28, 2026
Updated Sep 13, 2026
Reserved Aug 27, 2026
CISA Vulnrichment
Updated Aug 31, 2026
NVD
Status Analyzed
Modified Sep 14, 2026
Red Hat
Severity n/a
Public date n/a