peter bassill · operator
$ cve CVE-2023-27351 JSON

CVE-2023-27351 KEV

7.5
HIGH · CVSS 3.1 · EPSS 78.1% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2026-05-04.

Description

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS78.05% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-287
On CISA KEVyes — remediate by 2026-05-04
Public exploitnone known
Published2023-04-20
Last modified2026-06-17

CISA KEV

NamePaperCut NG/MF Improper Authentication Vulnerability
Added2026-04-20
Due2026-05-04
Vendor / productPaperCut / NG/MF
Ransomware useknown

Affected (2)

VendorProduct
papercutpapercut mf
papercutpapercut ng

References

→ the Explorer  ·  watch your stack  ·  NVD