
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-81578 is an improper access control (authentication bypass) vulnerability in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions before access validation checks complete, allowing an unauthenticated attacker to modify certain system configurations. The vulnerability affects PaperCut MF/NG versions prior to 24.1.10, 25.0.13, and 26.0.5, and was publicly disclosed on August 28, 2026. It carries a CVSS v4.0 base score of 8.8 (High) (GitHub Advisory, PaperCut Advisory).
The root cause is classified as CWE-305 (Authentication Bypass by Primary Weakness), where the authentication algorithm itself is sound but a separate weakness in the implementation allows it to be bypassed. Specifically, the PaperCut web management interface — built on the Apache Tapestry framework — processes certain administrative requests in a way that backend actions are triggered before access validation is fully completed, a condition described as "Tapestry request confusion" by researchers (CTI Pilot). The attack vector is fully network-based, requires no privileges, no user interaction, and no special attack requirements, making it trivially automatable. CVE-2026-81578 is frequently chained with a companion vulnerability, CVE-2026-82078 (dynamic class loading), to achieve pre-authentication remote code execution (The Hacker News, Dev.to Analysis).
Successful exploitation allows an unauthenticated remote attacker to modify system configurations on the PaperCut MF/NG server, with high integrity impact and low confidentiality and availability impact on the vulnerable system. When chained with CVE-2026-82078, attackers can escalate to full pre-authentication remote code execution, enabling complete server compromise, credential theft, lateral movement within the network, and potential ransomware deployment (Huntress, eSentire). PaperCut is widely deployed in enterprise, education, and government environments, meaning a large number of internet-facing print management servers are at risk (Rapid7).
CVE-2026-81578 has been actively exploited in the wild as a zero-day, with exploitation reported prior to the initial patch release and continuing after the first fix was found to be bypassable, necessitating a second emergency patch (BleepingComputer, SecurityWeek). A public detection/scanning tool (not a full exploit) is available on GitHub (GitHub PoC), and Nessus detection plugins (IDs 341347 and 341348) have been released. The EPSS score is approximately 0.39% (32nd percentile). The NVD SSVC assessment marks the vulnerability as automatable. No specific threat actor attribution has been publicly confirmed, though exploitation has been reported by multiple threat intelligence sources including Threadlinqs and ReliaQuest (Threadlinqs).
cmd.exe, powershell.exe, bash, curl, wget); unexpected Java class loading events in application logs.PaperCut has released patched versions addressing CVE-2026-81578: 24.1.10, 25.0.13, and 26.0.5. Notably, the initial patch was found to be bypassable, and PaperCut issued a second emergency patch — organizations should ensure they are running the latest fixed release and not just the first patch (BleepingComputer, PaperCut Advisory). As a network-level workaround, restrict access to the PaperCut web management interface (ports 9191/9192) to trusted IP addresses only, and avoid exposing the admin interface directly to the internet. Monitor administrative function requests for anomalous unauthenticated activity as an additional detection measure.
The vulnerability generated significant industry attention, with Rapid7, Huntress, eSentire, and SecurityWeek all publishing analyses and emergency advisories shortly after disclosure (Rapid7, Huntress, SecurityWeek). The fact that the initial patch was bypassed and a second emergency patch was required drew particular criticism and concern from the security community, with coverage from BleepingComputer, The Hacker News, The Record, and multiple national CERTs including NHS Digital (UK) and the Canadian Centre for Cyber Security (NHS Digital, Canadian CCCS). Social media discussion was active on LinkedIn and Mastodon, with researchers highlighting the pre-auth RCE chain formed by combining CVE-2026-81578 with CVE-2026-82078.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."