CVE-2026-6418
PaperCut NG vulnerability analysis and mitigation

Overview

CVE-2026-6418 is an Absolute Path Traversal vulnerability in the Shared Account Synchronization component of PaperCut MF and PaperCut NG. Discovered and disclosed on May 5, 2026, it affects PaperCut MF and NG versions prior to 25.0.11 (specifically confirmed in version 25.0.4). An authenticated administrative user can specify arbitrary file paths on the local file system during account synchronization configuration, enabling unauthorized reading of sensitive files. It carries a CVSS v3.1 base score of 4.9 (Medium) and a CVSS v4.0 base score of 4.6 (Medium) (GitHub Advisory, PaperCut Advisory).

Technical details

The root cause is a lack of proper path validation and sanitization in the Shared Account Synchronization component, classified as CWE-36 (Absolute Path Traversal) and CWE-552 (Files or Directories Accessible to External Parties). An authenticated administrator can configure the synchronization source path to point to arbitrary locations on the server's local file system — such as /etc/passwd, system configuration files, or application credential stores — rather than the intended account data directory. When the synchronization process is triggered, PaperCut attempts to parse the specified file and surfaces its contents within the application's account management interface, effectively exfiltrating the file's data to the attacker. Exploitation requires high privileges (administrative access) and the presence of attack requirements (an existing administrative session), limiting the attack surface to compromised or malicious administrators (GitHub Advisory, PaperCut Advisory).

Impact

Successful exploitation results in unauthorized disclosure of sensitive text-based files accessible to the PaperCut service account, including system configuration files, credential stores, and application secrets. The vulnerability has a high confidentiality impact on subsequent systems (e.g., the underlying OS or network infrastructure) while leaving integrity and availability unaffected. Depending on the service account's permissions, an attacker could enumerate directory structures and harvest credentials or configuration details that could facilitate lateral movement to other systems (GitHub Advisory, PaperCut Advisory).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.033–0.043%, placing it in the 13th percentile for exploitation likelihood within 30 days. Exploitation is constrained by the requirement for high-privilege (administrative) access, significantly reducing the pool of potential attackers.

Exploitation steps

  1. Gain Administrative Access: Obtain valid PaperCut MF/NG administrative credentials through phishing, credential stuffing, or compromise of an existing admin account on a vulnerable instance (version < 25.0.11).
  2. Navigate to Shared Account Synchronization: Log into the PaperCut admin interface and navigate to the Shared Account Synchronization configuration panel within the account management section.
  3. Specify Arbitrary File Path: In the source path field for account data synchronization, enter an absolute path to a sensitive file on the server's local file system (e.g., /etc/passwd, /etc/shadow, application configuration files, or PaperCut's own credential/config files).
  4. Trigger Synchronization: Initiate the synchronization process. The application will attempt to parse the contents of the specified file as account data.
  5. Harvest Exposed Data: Review the account management interface, where the parsed file contents are surfaced, allowing the attacker to read sensitive system or configuration information (GitHub Advisory, PaperCut Advisory).

Indicators of compromise

  • Logs: PaperCut application logs showing synchronization events with source paths pointing to system directories (e.g., /etc/, /var/, C:\Windows\System32\) rather than expected account data directories; audit log entries for administrative configuration changes to the Shared Account Synchronization source path.
  • Application Behavior: Unexpected entries or parsing errors in the account management interface corresponding to system file contents (e.g., user account entries resembling /etc/passwd format).
  • File System: Access timestamps updated on sensitive system files (e.g., /etc/passwd, application config files) coinciding with PaperCut synchronization events, attributable to the PaperCut service account.
  • Network: Administrative logins to the PaperCut web interface from unusual IP addresses or at unusual times, particularly followed by synchronization activity.

Mitigation and workarounds

PaperCut has released a patch in version 25.0.11 for both PaperCut MF and PaperCut NG; upgrading to this version or later is the primary recommended remediation (PaperCut Advisory). As interim mitigations, organizations should restrict administrative access to PaperCut to only trusted and necessary personnel, implement file system access controls to limit what files the PaperCut service account can read, and monitor audit logs for suspicious changes to the Shared Account Synchronization source path configuration. Network-level controls (e.g., restricting access to the PaperCut admin interface) can further reduce exposure.

Community reactions

The vulnerability was assigned and disclosed by PaperCut itself, with a security bulletin published in May 2026 (PaperCut Advisory). A technical write-up was published by Infinit Security shortly after disclosure (Infinit Security). Community and media reaction has been limited given the moderate severity rating, the requirement for administrative privileges, and the absence of active exploitation or a public PoC.

Additional resources


SourceThis report was generated using AI

Related PaperCut NG vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-39470HIGH7.2
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_ng
NoYesNov 22, 2024
CVE-2024-9672MEDIUM6.3
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_ng
NoYesDec 10, 2024
CVE-2026-6418MEDIUM4.6
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NoYesMay 05, 2026
CVE-2026-6180MEDIUM4.1
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NoYesMay 05, 2026
CVE-2026-4794LOW2.1
  • PaperCut NG logoPaperCut NG
  • cpe:2.3:a:papercut:papercut_mf
NoYesMar 31, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management