← Back to overview

PaperCut NG/MF contains a critical unsafe reflection vulnerability (CVE-2026-82078) that allows attackers to manipulate system configuration parameters and execute arbitrary Java bytecode on the application classpath. The execution occurs under the security context of the PaperCut server process, granting significant privileges to a potential attacker. This vulnerability can be chained with CVE-2026-81578 to increase attack impact. CISA has flagged this vulnerability under BOD 26-04, which prioritizes security updates based on risk. PaperCut has issued an urgent security advisory urging immediate patching. Forensic triage requirements have also been outlined by CISA for affected organizations. The vulnerability poses a high risk to enterprise print management environments running PaperCut NG or MF.

Affected products

  • PaperCut MF
  • PaperCut NG

Related CVE's

  • CVE-2026-81578
  • CVE-2026-82078

Categories

  • Enterprise Applications
  • Web Technologies
  • Zero-Day Vulnerabilities