peter bassill · operator
$ cve CVE-2026-81578 JSON

CVE-2026-81578 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 4.5% (pctl 91)

Patch first

On CISA KEV — known exploited in the wild, due 2026-09-14.

Description

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.48% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-305
On CISA KEVyes — remediate by 2026-09-14
Public exploitnone known
Published2026-08-28
Last modified2026-09-14

CISA KEV

NamePaperCut NG/MF Missing Authentication for Critical Function Vulnerability
Added2026-08-31
Due2026-09-14
Vendor / productPaperCut / NG/MF
Ransomware usenone reported

Affected (2)

VendorProduct
papercutpapercut mf
papercutpapercut ng

References

→ the Explorer  ·  watch your stack  ·  NVD