peter bassill · operator
$ cve CVE-2026-82078 JSON

CVE-2026-82078 KEV

9.1
CRITICAL · CVSS 3.1 · EPSS 3.8% (pctl 90)

Patch first

On CISA KEV — known exploited in the wild, due 2026-09-14.

Description

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS3.84% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-470
On CISA KEVyes — remediate by 2026-09-14
Public exploitnone known
Published2026-08-28
Last modified2026-09-14

CISA KEV

NamePaperCut NG/MF Unsafe Reflection Vulnerability
Added2026-08-31
Due2026-09-14
Vendor / productPaperCut / NG/MF
Ransomware usenone reported

Affected (2)

VendorProduct
papercutpapercut mf
papercutpapercut ng

References

→ the Explorer  ·  watch your stack  ·  NVD