
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5115 is a session hijacking vulnerability affecting the PaperCut NG/MF embedded application specifically designed for Konica Minolta multi-function devices. The flaw stems from an insecure communication channel between the embedded application (which runs on the device's touch screen) and the PaperCut server, enabling cleartext transmission of sensitive session data. It was internally discovered by PaperCut and disclosed on March 31, 2026. Affected versions include PaperCut MF prior to 25.0.5 and the Konica Minolta certified build prior to 25.0.9. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 3.6 (Low), reflecting differing scoring methodologies (GitHub Advisory, PaperCut Bulletin).
The root cause is classified as CWE-319 (Cleartext Transmission of Sensitive Information): the communication channel between the PaperCut NG/MF embedded application and the backend server does not use adequate encryption, allowing session tokens and other sensitive data to be transmitted in cleartext. An attacker with adjacent network access (e.g., on the same LAN segment as the multi-function device) could intercept this traffic using standard network sniffing techniques. Exploitation requires high attack complexity and passive user interaction — a legitimate user must be actively using the device's touch screen interface during the attack. No public proof-of-concept exploit code has been identified (GitHub Advisory, PaperCut Bulletin).
Successful exploitation could allow an adjacent network attacker to intercept session tokens or other sensitive information transmitted between the Konica Minolta device's embedded application and the PaperCut server, enabling session hijacking. Beyond session theft, the captured data could be leveraged to mount phishing attacks against end users interacting with the device. The impact is limited to confidentiality — there is no integrity or availability impact — but the exposure of session credentials could facilitate unauthorized access to print management functions or user account data (GitHub Advisory, PaperCut Bulletin).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.012% (0.000120), placing it in a very low probability tier for near-term exploitation. The CVSSv4 exploit maturity is rated "Unreported," and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for adjacent network positioning and high attack complexity (GitHub Advisory, PaperCut Bulletin).
PaperCut has released patched versions addressing this vulnerability: update PaperCut MF to version 25.0.5 or later, or to version 25.0.9 or later for Konica Minolta certified builds. As a network-level workaround, implement network segmentation to isolate multi-function devices from untrusted network segments, and consider deploying VPN or encrypted network communications for device-to-server traffic. Organizations should prioritize patching devices in environments where the MFD network segment is accessible to untrusted users or shared infrastructure (PaperCut Bulletin, GitHub Advisory).
The vulnerability was internally discovered and disclosed by PaperCut, with the security bulletin published in March 2026. Community aggregators such as CVEFeed.io and ENISA's EUVD catalogued the issue shortly after disclosure. No significant independent researcher commentary, social media discussion, or major media coverage has been identified, consistent with the low EPSS score and absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."