Critical CVE-2026-81578, CVE-2026-82078 — PaperCut print management servers have an unauthenticated configuration-change bypass that chains with an unsafe class-loading bug into code execution. Both are exploited. Fixed in PaperCut 24.1.10, 25.0.13 and 26.0.5.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: PaperCut NG and MF run print management in thousands of schools and offices. An unauthenticated attacker can change system settings through the admin web interface (CVE-2026-81578), and one of those settings lets them load arbitrary Java code (CVE-2026-82078, CVSS 9.4). Together that's remote code execution on the print server, which usually runs with high privileges on Windows. Upgrade to 24.1.10, 25.0.13 or 26.0.5.
| CVE-2026-81578 | Admin web interface acts on requests before access checks finish → unauthenticated config changes. CVSS 4.0: 8.8 |
|---|---|
| CVE-2026-82078 | Database connector loads any driver class named in config → arbitrary Java bytecode execution. CVSS 4.0: 9.4 |
| Affected | PaperCut NG/MF before 24.1.10, 25.0.0–25.0.12, 26.0.0–26.0.4 |
| Fixed in | 24.1.10 · 25.0.13 · 26.0.5 |
| Exploited? | Yes, both on CISA KEV 2026-08-31 (PaperCut rated it an “urgent” advisory) |
CVE-2026-81578: under specific conditions, the PaperCut admin web interface starts carrying out administrative actions before it has finished checking whether the requester is allowed to. An unauthenticated attacker can use that window to change certain system configuration values.
CVE-2026-82078: PaperCut’s database connection utilities load whatever driver class name the configuration says, with no allowlist. Once an attacker can set that configuration value (see above), they can make the server instantiate a class of their choosing and run code as the PaperCut service.
PaperCut has been here before: a similar chain in 2023 was widely used by ransomware groups. Print servers often run as SYSTEM and sit inside the network with broad access, which makes them a valuable foothold.
Log in to the PaperCut admin interface: the version is shown under About. Or check the server.properties/install directory for the release number. Vulnerable if below 24.1.10 (24.x and older), 25.0.0–25.0.12, or 26.0.0–26.0.4.
PaperCut Hive and PaperCut Pocket are cloud products; this advisory is for NG and MF servers you run.
cmd.exe, powershell.exe) spawned by the PaperCut service.Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.