
PEACH
Un framework di isolamento del tenant
CVE-2026-82078 is an unsafe dynamic class loading (unsafe reflection) vulnerability in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers, enabling execution of arbitrary Java bytecode under the PaperCut server process security context. Disclosed on August 28, 2026, it affects PaperCut MF/NG versions prior to 24.1.9, 25.0.12, and 26.0.4. It carries a CVSS v3.1 score of 9.1 (Critical) and a CVSS v4.0 score of 9.4 (Critical) (GitHub Advisory, CISA KEV, PaperCut Advisory).
The root cause is classified as CWE-470 (Use of Externally-Controlled Input to Select Classes or Code / 'Unsafe Reflection'). PaperCut's database connection utilities accept a configurable driver class name and instantiate it via Java reflection without restricting the input to an approved allowlist. An attacker who can manipulate system configuration parameters — for example, via the external user lookup configuration interface — can specify an arbitrary class name present on the application classpath, causing the server to load and execute that class's bytecode. In practice, CVE-2026-82078 is chained with CVE-2026-81578 (an authentication bypass) to achieve pre-authentication remote code execution: the auth bypass provides access to the configuration endpoint, and this vulnerability provides the code execution primitive via H2/Derby JDBC URL injection on version 26.x or Derby class-drop on versions 24.x–25.x (Metasploit PR, GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary Java bytecode with the full privileges of the PaperCut server process — SYSTEM on Windows or the papercut service account on Linux — resulting in complete confidentiality, integrity, and availability compromise of the affected host. Attackers have been observed deploying remote access tools, stealing credentials, and exfiltrating data from compromised print servers, with particular targeting of schools and universities in the US and Europe. The changed scope (CVSS S:C) reflects that exploitation can impact systems beyond the PaperCut application itself, enabling lateral movement within the network (CISA KEV, PaperCut Advisory).
CVE-2026-82078 is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities catalog on August 31, 2026, with a remediation due date of September 14, 2026 (CISA KEV). A fully functional Metasploit exploit module (exploit/multi/http/papercut_ng_external_user_lookup_rce) was merged on September 3, 2026, chaining CVE-2026-81578 (auth bypass) with CVE-2026-82078 to achieve unauthenticated RCE on versions 24.x–26.x (Metasploit PR). Additional public PoC code exists on GitHub (e.g., yora1928/PaperCut-CVE-2026-81578-82078). The EPSS score is approximately 1.69%, and exploitation has been linked to data theft campaigns targeting education sector organizations. PaperCut issued two emergency patches before a third was required after the first fix was bypassed by researchers.
papercut on Linux), enabling reverse shell establishment, credential harvesting, or further payload deployment..class or .csv files dropped in the PaperCut installation directory (used as Derby bootstrap artifacts on versions 24.x–25.x); new or modified files in the PaperCut data directory; web shells or remote access tool binaries written to disk by the server process.cmd.exe, powershell.exe, bash, curl, wget); remote access tools (e.g., AnyDesk, ScreenConnect) installed or executed under the PaperCut service account context.SYSTEM account or PaperCut service account; registry run keys modified by the PaperCut process (CISA KEV, Metasploit PR).PaperCut has released patched versions: 24.1.9, 25.0.12, and 26.0.4 for both PaperCut MF and PaperCut NG — upgrading to these versions is the primary recommended remediation (PaperCut Advisory). Note that PaperCut's first emergency patch was bypassed by researchers, necessitating a second (and subsequently a third) patch release; organizations should ensure they are on the latest available build. As interim workarounds: restrict network access to the PaperCut administration interface (port 9191) to trusted IP ranges only; disable external user lookup if not required; and monitor configuration parameters for unauthorized changes. CISA's BOD 26-04 mandates federal agencies apply mitigations by September 14, 2026 (CISA KEV).
PaperCut issued an urgent security advisory on August 27–28, 2026, acknowledging active exploitation and releasing emergency patches; the company subsequently issued a second and third emergency patch after the initial fix was bypassed (PaperCut Advisory). Rapid7 published an ETR blog post detailing the exploit chain and contributed the Metasploit module, noting the vulnerability was being exploited as a zero-day before patches were available (Metasploit PR). Huntress, Horizon3.ai, watchTowr, eSentire, Qualys, and SOCRadar all published technical analyses and detection guidance. Security media including The Hacker News, BleepingComputer, SecurityWeek, and Security Affairs provided extensive coverage, highlighting the targeting of schools and universities and the credential theft campaigns. The Shadowserver Foundation reported active scanning of PaperCut servers, and community discussion on Reddit and Mastodon reflected significant concern about the patch bypass and the speed of weaponization.
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."