
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6418 is an Absolute Path Traversal vulnerability in the Shared Account Synchronization component of PaperCut MF and PaperCut NG. Discovered and disclosed on May 5, 2026, it affects PaperCut MF and NG versions prior to 25.0.11 (specifically confirmed in version 25.0.4). An authenticated administrative user can specify arbitrary file paths on the local file system during account synchronization configuration, enabling unauthorized reading of sensitive files. It carries a CVSS v3.1 base score of 4.9 (Medium) and a CVSS v4.0 base score of 4.6 (Medium) (GitHub Advisory, PaperCut Advisory).
The root cause is a lack of proper path validation and sanitization in the Shared Account Synchronization component, classified as CWE-36 (Absolute Path Traversal) and CWE-552 (Files or Directories Accessible to External Parties). An authenticated administrator can configure the synchronization source path to point to arbitrary locations on the server's local file system — such as /etc/passwd, system configuration files, or application credential stores — rather than the intended account data directory. When the synchronization process is triggered, PaperCut attempts to parse the specified file and surfaces its contents within the application's account management interface, effectively exfiltrating the file's data to the attacker. Exploitation requires high privileges (administrative access) and the presence of attack requirements (an existing administrative session), limiting the attack surface to compromised or malicious administrators (GitHub Advisory, PaperCut Advisory).
Successful exploitation results in unauthorized disclosure of sensitive text-based files accessible to the PaperCut service account, including system configuration files, credential stores, and application secrets. The vulnerability has a high confidentiality impact on subsequent systems (e.g., the underlying OS or network infrastructure) while leaving integrity and availability unaffected. Depending on the service account's permissions, an attacker could enumerate directory structures and harvest credentials or configuration details that could facilitate lateral movement to other systems (GitHub Advisory, PaperCut Advisory).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.033–0.043%, placing it in the 13th percentile for exploitation likelihood within 30 days. Exploitation is constrained by the requirement for high-privilege (administrative) access, significantly reducing the pool of potential attackers.
/etc/passwd, /etc/shadow, application configuration files, or PaperCut's own credential/config files)./etc/, /var/, C:\Windows\System32\) rather than expected account data directories; audit log entries for administrative configuration changes to the Shared Account Synchronization source path./etc/passwd format)./etc/passwd, application config files) coinciding with PaperCut synchronization events, attributable to the PaperCut service account.PaperCut has released a patch in version 25.0.11 for both PaperCut MF and PaperCut NG; upgrading to this version or later is the primary recommended remediation (PaperCut Advisory). As interim mitigations, organizations should restrict administrative access to PaperCut to only trusted and necessary personnel, implement file system access controls to limit what files the PaperCut service account can read, and monitor audit logs for suspicious changes to the Shared Account Synchronization source path configuration. Network-level controls (e.g., restricting access to the PaperCut admin interface) can further reduce exposure.
The vulnerability was assigned and disclosed by PaperCut itself, with a security bulletin published in May 2026 (PaperCut Advisory). A technical write-up was published by Infinit Security shortly after disclosure (Infinit Security). Community and media reaction has been limited given the moderate severity rating, the requirement for administrative privileges, and the absence of active exploitation or a public PoC.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."