Security
Loading…

CVE-2026-82078

CRITICALCVSS 9.1Known Exploited
Description

PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.

Timeline
Published:August 28th, 2026 4:18 PM
Last modified:September 1st, 2026 4:18 AM
Added to KEV:August 31st, 2026
CVSS Scoring

CVSS v3: 9.1 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

papercut

Products

papercut_mfpapercut_ng
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute