CVE-2026-5115
PaperCut MF vulnerability analysis and mitigation

Overview

CVE-2026-5115 is a session hijacking vulnerability affecting the PaperCut NG/MF embedded application specifically designed for Konica Minolta multi-function devices. The flaw stems from an insecure communication channel between the embedded application (which runs on the device's touch screen) and the PaperCut server, enabling cleartext transmission of sensitive session data. It was internally discovered by PaperCut and disclosed on March 31, 2026. Affected versions include PaperCut MF prior to 25.0.5 and the Konica Minolta certified build prior to 25.0.9. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 3.6 (Low), reflecting differing scoring methodologies (GitHub Advisory, PaperCut Bulletin).

Technical details

The root cause is classified as CWE-319 (Cleartext Transmission of Sensitive Information): the communication channel between the PaperCut NG/MF embedded application and the backend server does not use adequate encryption, allowing session tokens and other sensitive data to be transmitted in cleartext. An attacker with adjacent network access (e.g., on the same LAN segment as the multi-function device) could intercept this traffic using standard network sniffing techniques. Exploitation requires high attack complexity and passive user interaction — a legitimate user must be actively using the device's touch screen interface during the attack. No public proof-of-concept exploit code has been identified (GitHub Advisory, PaperCut Bulletin).

Impact

Successful exploitation could allow an adjacent network attacker to intercept session tokens or other sensitive information transmitted between the Konica Minolta device's embedded application and the PaperCut server, enabling session hijacking. Beyond session theft, the captured data could be leveraged to mount phishing attacks against end users interacting with the device. The impact is limited to confidentiality — there is no integrity or availability impact — but the exposure of session credentials could facilitate unauthorized access to print management functions or user account data (GitHub Advisory, PaperCut Bulletin).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.012% (0.000120), placing it in a very low probability tier for near-term exploitation. The CVSSv4 exploit maturity is rated "Unreported," and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for adjacent network positioning and high attack complexity (GitHub Advisory, PaperCut Bulletin).

Exploitation steps

  1. Reconnaissance: Identify Konica Minolta multi-function devices on the target network running PaperCut NG/MF embedded application versions prior to 25.0.5 (or 25.0.9 for KM-certified builds) using network scanning tools such as Nmap.
  2. Gain adjacent network access: Position on the same network segment as the target multi-function device, either through physical access, a compromised host on the LAN, or a rogue wireless access point near the device.
  3. Capture network traffic: Use a packet capture tool (e.g., Wireshark, tcpdump) to intercept traffic between the Konica Minolta device and the PaperCut server, targeting the communication channel used by the embedded application.
  4. Extract session tokens: Analyze the captured cleartext traffic to identify session identifiers or authentication tokens transmitted without encryption.
  5. Hijack session or conduct phishing: Replay the captured session token to impersonate the authenticated user within the PaperCut system, or use intercepted user information to craft a targeted phishing attack against the end user (GitHub Advisory, PaperCut Bulletin).

Indicators of compromise

  • Network: Unexpected ARP spoofing or man-in-the-middle activity on network segments hosting Konica Minolta multi-function devices; unencrypted HTTP traffic observed between MFD devices and the PaperCut server on monitored network taps or IDS sensors.
  • Logs: PaperCut server logs showing session activity from IP addresses inconsistent with the physical location of the multi-function device; duplicate or replayed session tokens appearing in server-side access logs.
  • Network: Unusual packet capture or promiscuous mode activity detected on switches or network monitoring tools near MFD device segments.
  • Logs: Authentication events in PaperCut logs showing the same user session active from multiple source IPs simultaneously, potentially indicating session token reuse.

Mitigation and workarounds

PaperCut has released patched versions addressing this vulnerability: update PaperCut MF to version 25.0.5 or later, or to version 25.0.9 or later for Konica Minolta certified builds. As a network-level workaround, implement network segmentation to isolate multi-function devices from untrusted network segments, and consider deploying VPN or encrypted network communications for device-to-server traffic. Organizations should prioritize patching devices in environments where the MFD network segment is accessible to untrusted users or shared infrastructure (PaperCut Bulletin, GitHub Advisory).

Community reactions

The vulnerability was internally discovered and disclosed by PaperCut, with the security bulletin published in March 2026. Community aggregators such as CVEFeed.io and ENISA's EUVD catalogued the issue shortly after disclosure. No significant independent researcher commentary, social media discussion, or major media coverage has been identified, consistent with the low EPSS score and absence of active exploitation.

Additional resources


SourceThis report was generated using AI

Related PaperCut MF vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-9672MEDIUM6.3
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_ng
NoYesDec 10, 2024
CVE-2026-6418MEDIUM4.6
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NoYesMay 05, 2026
CVE-2026-6180MEDIUM4.1
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NoYesMay 05, 2026
CVE-2026-5115LOW3.6
  • PaperCut MF logoPaperCut MF
  • cpe:2.3:a:papercut:papercut_mf
NoYesMar 31, 2026
CVE-2026-4794LOW2.1
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NoYesMar 31, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management