Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-82078

PaperCut NG/MF Unsafe Class-Loading RCE

PaperCut NG/MF (CVSS 9.4 Critical): unsafe dynamic class-loading enables unauthenticated RCE. Actively exploited; apply Emergency Patch Release 2 immediately.

cat cve-2026-82078.json
Vendor
PaperCut Software
Product
PaperCut NG and PaperCut MF (versions 24, 25, 26)
CVSS
9.4
EPSS (exploit probability)
N/A
Status
patched
Published

CVE-2026-82078 is a critical flaw in PaperCut NG and PaperCut MF (CVSS 9.4) affecting versions 24, 25, and 26. The application loads database driver classes based on configurable driver names without validating them against an approved allowlist. An attacker who has bypassed authentication via CVE-2026-81578 can reconfigure external database settings, loading arbitrary Java classes and ultimately achieving remote code execution on the server.

PaperCut has not disclosed the full technical class of this vulnerability; the CVSS 9.4 rating reflects the combination of unauthenticated precondition (via CVE-2026-81578) and full RCE outcome. Per Rapid7’s technical report, the attack chain was reproducible against Emergency Patch Release 1.

Active exploitation was confirmed in the wild before the initial patch shipped. PaperCut’s Emergency Patch Release 2 includes additional hardening to close bypass paths identified by Huntress and watchTowr researchers.

Patch: Apply Emergency Patch Release 2 for versions 24, 25, or 26. Version 23 and older users should upgrade to a supported release. Patch links in PaperCut’s updated bulletin.