CVE-2026-6418
PaperCut NG Analisi e mitigazione delle vulnerabilità

Panoramica

CVE-2026-6418 is an Absolute Path Traversal vulnerability in the Shared Account Synchronization component of PaperCut MF and PaperCut NG. Discovered and disclosed on May 5, 2026, it affects PaperCut MF and NG versions prior to 25.0.11 (specifically confirmed in version 25.0.4). An authenticated administrative user can specify arbitrary file paths on the local file system during account synchronization configuration, enabling unauthorized reading of sensitive files. It carries a CVSS v3.1 base score of 4.9 (Medium) and a CVSS v4.0 base score of 4.6 (Medium) (GitHub Advisory, PaperCut Advisory).

Dettagli tecnici

The root cause is a lack of proper path validation and sanitization in the Shared Account Synchronization component, classified as CWE-36 (Absolute Path Traversal) and CWE-552 (Files or Directories Accessible to External Parties). An authenticated administrator can configure the synchronization source path to point to arbitrary locations on the server's local file system — such as /etc/passwd, system configuration files, or application credential stores — rather than the intended account data directory. When the synchronization process is triggered, PaperCut attempts to parse the specified file and surfaces its contents within the application's account management interface, effectively exfiltrating the file's data to the attacker. Exploitation requires high privileges (administrative access) and the presence of attack requirements (an existing administrative session), limiting the attack surface to compromised or malicious administrators (GitHub Advisory, PaperCut Advisory).

Impatto

Successful exploitation results in unauthorized disclosure of sensitive text-based files accessible to the PaperCut service account, including system configuration files, credential stores, and application secrets. The vulnerability has a high confidentiality impact on subsequent systems (e.g., the underlying OS or network infrastructure) while leaving integrity and availability unaffected. Depending on the service account's permissions, an attacker could enumerate directory structures and harvest credentials or configuration details that could facilitate lateral movement to other systems (GitHub Advisory, PaperCut Advisory).

Sfruttabilità

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.033–0.043%, placing it in the 13th percentile for exploitation likelihood within 30 days. Exploitation is constrained by the requirement for high-privilege (administrative) access, significantly reducing the pool of potential attackers.

Passaggi di sfruttamento

  1. Gain Administrative Access: Obtain valid PaperCut MF/NG administrative credentials through phishing, credential stuffing, or compromise of an existing admin account on a vulnerable instance (version < 25.0.11).
  2. Navigate to Shared Account Synchronization: Log into the PaperCut admin interface and navigate to the Shared Account Synchronization configuration panel within the account management section.
  3. Specify Arbitrary File Path: In the source path field for account data synchronization, enter an absolute path to a sensitive file on the server's local file system (e.g., /etc/passwd, /etc/shadow, application configuration files, or PaperCut's own credential/config files).
  4. Trigger Synchronization: Initiate the synchronization process. The application will attempt to parse the contents of the specified file as account data.
  5. Harvest Exposed Data: Review the account management interface, where the parsed file contents are surfaced, allowing the attacker to read sensitive system or configuration information (GitHub Advisory, PaperCut Advisory).

Indicatori di compromesso

  • Logs: PaperCut application logs showing synchronization events with source paths pointing to system directories (e.g., /etc/, /var/, C:\Windows\System32\) rather than expected account data directories; audit log entries for administrative configuration changes to the Shared Account Synchronization source path.
  • Application Behavior: Unexpected entries or parsing errors in the account management interface corresponding to system file contents (e.g., user account entries resembling /etc/passwd format).
  • File System: Access timestamps updated on sensitive system files (e.g., /etc/passwd, application config files) coinciding with PaperCut synchronization events, attributable to the PaperCut service account.
  • Network: Administrative logins to the PaperCut web interface from unusual IP addresses or at unusual times, particularly followed by synchronization activity.

Mitigazione e soluzioni alternative

PaperCut has released a patch in version 25.0.11 for both PaperCut MF and PaperCut NG; upgrading to this version or later is the primary recommended remediation (PaperCut Advisory). As interim mitigations, organizations should restrict administrative access to PaperCut to only trusted and necessary personnel, implement file system access controls to limit what files the PaperCut service account can read, and monitor audit logs for suspicious changes to the Shared Account Synchronization source path configuration. Network-level controls (e.g., restricting access to the PaperCut admin interface) can further reduce exposure.

Reazioni della comunità

The vulnerability was assigned and disclosed by PaperCut itself, with a security bulletin published in May 2026 (PaperCut Advisory). A technical write-up was published by Infinit Security shortly after disclosure (Infinit Security). Community and media reaction has been limited given the moderate severity rating, the requirement for administrative privileges, and the absence of active exploitation or a public PoC.

Risorse aggiuntive


FonteQuesto report è stato generato utilizzando l'intelligenza artificiale

Imparentato PaperCut NG Vulnerabilità:

CVE ID

Severità

Punteggio

Tecnologie

Nome del componente

Exploit CISA KEV

Ha la correzione

Data di pubblicazione

CVE-2026-82078CRITICAL9.4
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
Aug 28, 2026
CVE-2026-81578HIGH8.8
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
Aug 28, 2026
CVE-2026-6418MEDIUM4.6
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NoMay 05, 2026
CVE-2026-6180MEDIUM4.1
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NoMay 05, 2026
CVE-2026-4794LOW2.1
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NoMar 31, 2026

Valutazione gratuita delle vulnerabilità

Benchmark della tua posizione di sicurezza del cloud

Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.

Richiedi valutazione

Richiedi una demo personalizzata

Pronti a vedere Wiz in azione?

"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
David EstlickCISO (CISO)
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
Adam FletcherResponsabile della sicurezza
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."
Greg PoniatowskiResponsabile della gestione delle minacce e delle vulnerabilità