CVE-2026-6418
PaperCut NG Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-6418 is an Absolute Path Traversal vulnerability in the Shared Account Synchronization component of PaperCut MF and PaperCut NG. Discovered and disclosed on May 5, 2026, it affects PaperCut MF and NG versions prior to 25.0.11 (specifically confirmed in version 25.0.4). An authenticated administrative user can specify arbitrary file paths on the local file system during account synchronization configuration, enabling unauthorized reading of sensitive files. It carries a CVSS v3.1 base score of 4.9 (Medium) and a CVSS v4.0 base score of 4.6 (Medium) (GitHub Advisory, PaperCut Advisory).

Detalhes técnicos

The root cause is a lack of proper path validation and sanitization in the Shared Account Synchronization component, classified as CWE-36 (Absolute Path Traversal) and CWE-552 (Files or Directories Accessible to External Parties). An authenticated administrator can configure the synchronization source path to point to arbitrary locations on the server's local file system — such as /etc/passwd, system configuration files, or application credential stores — rather than the intended account data directory. When the synchronization process is triggered, PaperCut attempts to parse the specified file and surfaces its contents within the application's account management interface, effectively exfiltrating the file's data to the attacker. Exploitation requires high privileges (administrative access) and the presence of attack requirements (an existing administrative session), limiting the attack surface to compromised or malicious administrators (GitHub Advisory, PaperCut Advisory).

Impacto

Successful exploitation results in unauthorized disclosure of sensitive text-based files accessible to the PaperCut service account, including system configuration files, credential stores, and application secrets. The vulnerability has a high confidentiality impact on subsequent systems (e.g., the underlying OS or network infrastructure) while leaving integrity and availability unaffected. Depending on the service account's permissions, an attacker could enumerate directory structures and harvest credentials or configuration details that could facilitate lateral movement to other systems (GitHub Advisory, PaperCut Advisory).

Exploração

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.033–0.043%, placing it in the 13th percentile for exploitation likelihood within 30 days. Exploitation is constrained by the requirement for high-privilege (administrative) access, significantly reducing the pool of potential attackers.

Etapas de exploração

  1. Gain Administrative Access: Obtain valid PaperCut MF/NG administrative credentials through phishing, credential stuffing, or compromise of an existing admin account on a vulnerable instance (version < 25.0.11).
  2. Navigate to Shared Account Synchronization: Log into the PaperCut admin interface and navigate to the Shared Account Synchronization configuration panel within the account management section.
  3. Specify Arbitrary File Path: In the source path field for account data synchronization, enter an absolute path to a sensitive file on the server's local file system (e.g., /etc/passwd, /etc/shadow, application configuration files, or PaperCut's own credential/config files).
  4. Trigger Synchronization: Initiate the synchronization process. The application will attempt to parse the contents of the specified file as account data.
  5. Harvest Exposed Data: Review the account management interface, where the parsed file contents are surfaced, allowing the attacker to read sensitive system or configuration information (GitHub Advisory, PaperCut Advisory).

Indicadores de compromisso

  • Logs: PaperCut application logs showing synchronization events with source paths pointing to system directories (e.g., /etc/, /var/, C:\Windows\System32\) rather than expected account data directories; audit log entries for administrative configuration changes to the Shared Account Synchronization source path.
  • Application Behavior: Unexpected entries or parsing errors in the account management interface corresponding to system file contents (e.g., user account entries resembling /etc/passwd format).
  • File System: Access timestamps updated on sensitive system files (e.g., /etc/passwd, application config files) coinciding with PaperCut synchronization events, attributable to the PaperCut service account.
  • Network: Administrative logins to the PaperCut web interface from unusual IP addresses or at unusual times, particularly followed by synchronization activity.

Mitigação e soluções alternativas

PaperCut has released a patch in version 25.0.11 for both PaperCut MF and PaperCut NG; upgrading to this version or later is the primary recommended remediation (PaperCut Advisory). As interim mitigations, organizations should restrict administrative access to PaperCut to only trusted and necessary personnel, implement file system access controls to limit what files the PaperCut service account can read, and monitor audit logs for suspicious changes to the Shared Account Synchronization source path configuration. Network-level controls (e.g., restricting access to the PaperCut admin interface) can further reduce exposure.

Reações da comunidade

The vulnerability was assigned and disclosed by PaperCut itself, with a security bulletin published in May 2026 (PaperCut Advisory). A technical write-up was published by Infinit Security shortly after disclosure (Infinit Security). Community and media reaction has been limited given the moderate severity rating, the requirement for administrative privileges, and the absence of active exploitation or a public PoC.

Recursos adicionais


OrigemEste relatório foi gerado usando IA

Relacionado PaperCut NG Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-82078CRITICAL9.4
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_ng
SimSimAug 28, 2026
CVE-2026-81578HIGH8.8
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_ng
SimSimAug 28, 2026
CVE-2026-6418MEDIUM4.6
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NãoSimMay 05, 2026
CVE-2026-6180MEDIUM4.1
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NãoSimMay 05, 2026
CVE-2026-4794LOW2.1
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NãoSimMar 31, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades