Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

PaperCut NG/MF CVE-2026-81578 & CVE-2026-82078: Exploited Auth Bypass + Code Execution Chain

Critical CVE-2026-81578, CVE-2026-82078 — PaperCut print management servers have an unauthenticated configuration-change bypass that chains with an unsafe class-loading bug into code execution. Both are exploited. Fixed in PaperCut 24.1.10, 25.0.13 and 26.0.5.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: PaperCut NG and MF run print management in thousands of schools and offices. An unauthenticated attacker can change system settings through the admin web interface (CVE-2026-81578), and one of those settings lets them load arbitrary Java code (CVE-2026-82078, CVSS 9.4). Together that's remote code execution on the print server, which usually runs with high privileges on Windows. Upgrade to 24.1.10, 25.0.13 or 26.0.5.

CVE-2026-81578Admin web interface acts on requests before access checks finish → unauthenticated config changes. CVSS 4.0: 8.8
CVE-2026-82078Database connector loads any driver class named in config → arbitrary Java bytecode execution. CVSS 4.0: 9.4
AffectedPaperCut NG/MF before 24.1.10, 25.0.0–25.0.12, 26.0.0–26.0.4
Fixed in24.1.10 · 25.0.13 · 26.0.5
Exploited?Yes, both on CISA KEV 2026-08-31 (PaperCut rated it an “urgent” advisory)

How the chain works

CVE-2026-81578: under specific conditions, the PaperCut admin web interface starts carrying out administrative actions before it has finished checking whether the requester is allowed to. An unauthenticated attacker can use that window to change certain system configuration values.

CVE-2026-82078: PaperCut’s database connection utilities load whatever driver class name the configuration says, with no allowlist. Once an attacker can set that configuration value (see above), they can make the server instantiate a class of their choosing and run code as the PaperCut service.

PaperCut has been here before: a similar chain in 2023 was widely used by ransomware groups. Print servers often run as SYSTEM and sit inside the network with broad access, which makes them a valuable foothold.

Am I affected?

Log in to the PaperCut admin interface: the version is shown under About. Or check the server.properties/install directory for the release number. Vulnerable if below 24.1.10 (24.x and older), 25.0.0–25.0.12, or 26.0.0–26.0.4.

PaperCut Hive and PaperCut Pocket are cloud products; this advisory is for NG and MF servers you run.

How to patch

  1. Download the fixed release for your line (24.1.10, 25.0.13 or 26.0.5) from the PaperCut portal.
  2. Back up first: in the admin interface, use Options → Backups → Back up now.
  3. Run the installer over the existing install; it upgrades in place. Upgrade any site servers too.

If you can’t patch right away

  • Restrict access to the admin interface (TCP 9191/9192 by default) to admin workstations using Options → Advanced → Security → Allowed site server IP addresses and the Windows firewall.
  • Never expose the PaperCut server to the internet. If you need remote printing, use PaperCut’s cloud components or a VPN.

Check for compromise

  • Review Logs → Application Log for configuration changes (especially database settings) and admin actions you didn’t make.
  • Look for unfamiliar JAR files in the PaperCut install directory and child processes (cmd.exe, powershell.exe) spawned by the PaperCut service.
  • If you see signs of it, isolate the server and check for remote-access tools, new accounts and lateral movement. Past PaperCut exploitation led straight to ransomware.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories