Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-81578

PaperCut NG/MF Authentication Bypass

Authentication bypass in PaperCut NG/MF (CVSS 8.8) lets unauthenticated attackers access admin functions via malformed requests. Actively exploited; apply Emergency Patch Release 2.

cat cve-2026-81578.json
Vendor
PaperCut Software
Product
PaperCut NG and PaperCut MF (versions 24, 25, 26)
CVSS
8.8
EPSS (exploit probability)
N/A
Status
patched
Published

CVE-2026-81578 is an authentication bypass in PaperCut NG and PaperCut MF affecting versions 24, 25, and 26. Unauthenticated remote requests targeting administrative functions can trigger backend actions before access validation completes, allowing an attacker to bypass the login requirement entirely.

This flaw is the entry point for the two-CVE attack chain detailed in Rapid7’s analysis. Exploiting CVE-2026-81578 provides the unauthenticated access needed to weaponize the critical class-loading flaw in CVE-2026-82078.

Active exploitation was confirmed before the initial patch shipped. Researchers at Huntress and watchTowr identified bypass methods in PaperCut’s first emergency patch; Emergency Patch Release 2 addresses those gaps.

Patch: Apply Emergency Patch Release 2 for PaperCut NG/MF versions 24, 25, or 26. Version 23 and older users should upgrade to a supported release. Full guidance in PaperCut’s updated bulletin.