VMTech
Discuss a project

PaperCut NG and MF Bugs Are Being Chained for Remote Code Execution

PaperCut NG and MF Bugs Are Being Chained for Remote Code Execution

PaperCut issues a second emergency patch

Attackers are exploiting two vulnerabilities in PaperCut NG and PaperCut MF to bypass authentication and execute arbitrary code on affected servers. PaperCut has released a second emergency patch that adds hardening beyond its original emergency fix, while researchers report limited exploitation in customer environments.

The two disclosed issues are CVE-2026-82078, rated 9.4 on the CVSS scale, and CVE-2026-81578, rated 8.8. watchTowr said attackers are chaining both flaws to obtain remote code execution without authentication on susceptible instances.

CVE-2026-82078 is an unsafe dynamic class-loading issue in the products' database connection utilities. PaperCut NG and MF can instantiate database-driver classes from configurable driver names without validating them against an allowlist of approved drivers.

CVE-2026-81578 is an improper access-control vulnerability in the web management interface. Under specific conditions, unauthenticated remote requests aimed at administrative functions can trigger backend actions before access validation checks have completed.

How the authorization weakness is abused

Huntress researchers John Hammond and Andrew Brandt said a crafted request can refer to one page for the rendered response while invoking a component or action owned by another page. The authorization check can trust the rendered page and fail to enforce permissions needed by the component behind it.

That condition lets an unauthenticated request alter server configuration. In turn, an attacker can reach sensitive endpoints, trigger unsafe actions and run attacker-controlled Java code inside the PaperCut application process.

watchTowr also reported discovering multiple patch bypasses and an additional authentication-bypass vulnerability. The company said these findings were likely addressed in the second emergency patch, although PaperCut has not detailed the malicious activity exploiting the flaws.

Observed commands and defensive actions

Huntress observed attacks in two customer environments. The intruders ran Base64-encoded commands including whoami & ver to identify the account and operating system. In an incident recorded on August 27, 2026, a modified command added tasklist to collect running processes.

The activity also deployed an operating-system-agnostic Java .class file capable of running commands on Linux and Windows. It fingerprinted the host and collected a directory listing, writing the results to Udydn.out under /data/content/ relative to the installation directory. It then deleted that output file, server.log and /data/internal/derby.log.

Organizations running PaperCut NG or MF should remove public internet exposure, apply the latest patch and limit PaperCut Application Server web access to trusted IP addresses, a VPN or another controlled administrative path. Security teams can also hunt for Database error looking up cardID: VALUES CAST in logs as a potential indicator of compromise. The practical priority is to contain externally reachable instances and review affected servers for the observed activity.

#papercut#cybersecurity#vulnerability#remotecodeexecution
Open analytics
On the site 0 views
min read 3 28.08.2026
Instagram

PaperCut NG and MF Bugs Are Being Chained for Remote Code Execution

Open the post on Instagram ↗