CVE-2026-81578 is an unauthenticated improper access control / authentication bypass vulnerability in the web management interface of PaperCut MF/NG. Remote attackers can trigger administrative backend actions before access validation completes, modifying server configurations. It is actively exploited in the wild, listed in CISA KEV, and is frequently chained with CVE-2026-82078 to achieve pre-authentication RCE on the PaperCut Application Server.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-08-28
Added to CISA KEV: 2026-08-31 3 DAYS BETWEEN CVE AND KEV
CVE-2026-81578 is a critical improper access control vulnerability (CWE-306) affecting the web management interface of PaperCut MF and PaperCut NG print management software [5][8]. The flaw allows unauthenticated remote requests to trigger backend administrative actions before access validation checks are completed, enabling attackers to modify server configurations [7][10]. This vulnerability is highly significant because, when chained with CVE-2026-82078, it facilitates pre-authentication remote code execution (RCE) on the PaperCut Application Server [3].
We saw attackers successfully chain both CVE-2026-81578 and CVE-2026-82078 to gain Remote Code Execution on our PaperCut sensors. Exploitation followed a sequence of POST requests designed to bypass authentication, reconfigure the database connector to execute Groovy code, trigger the vulnerability,…
URGENT Security Advisory Status 10 Sep 2026, 2:00pm (AEST): Security maintenance releases published. These replace all emergency patches. Download links below. Read the Behind the Scenes blog post for the backstory. PaperCut Software security response team is investigating active exploitation of a v…
PaperCut released an Urgent Security Advisory to address two actively exploited vulnerabilities, tracked as CVE-2026-82078 & CVE-2026-81578, impacting all versions of PaperCut NG and PaperCut MF. When chained together, these vulnerabilities can enable pre-authentication remote code execution in the…
Attackers are actively exploiting two new PaperCut flaws (CVE-2026-81578, CVE-2026-82078) against U.S. and European schools to steal credentials and gain privileged access. Patch and hunt now.
CVE-2026-81578 is a missing-authentication flaw (CWE-306) in the web management interface of PaperCut NG and PaperCut MF, the print-management platform. An unauthenticated remote request reaches an administrative action before the access check completes, so an attacker with no credentials can rewrit…