PaperCut NG/MF Authentication Bypass
Authentication bypass in PaperCut NG/MF (CVSS 8.8) lets unauthenticated attackers access admin functions via malformed requests. Actively exploited; apply Emergency Patch Release 2.
- Vendor
- PaperCut Software
- Product
- PaperCut NG and PaperCut MF (versions 24, 25, 26)
- CVSS
- 8.8
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
CVE-2026-81578 is an authentication bypass in PaperCut NG and PaperCut MF affecting versions 24, 25, and 26. Unauthenticated remote requests targeting administrative functions can trigger backend actions before access validation completes, allowing an attacker to bypass the login requirement entirely.
This flaw is the entry point for the two-CVE attack chain detailed in Rapid7’s analysis. Exploiting CVE-2026-81578 provides the unauthenticated access needed to weaponize the critical class-loading flaw in CVE-2026-82078.
Active exploitation was confirmed before the initial patch shipped. Researchers at Huntress and watchTowr identified bypass methods in PaperCut’s first emergency patch; Emergency Patch Release 2 addresses those gaps.
Patch: Apply Emergency Patch Release 2 for PaperCut NG/MF versions 24, 25, or 26. Version 23 and older users should upgrade to a supported release. Full guidance in PaperCut’s updated bulletin.
