Knox CVE Database
/
CVE-2026-81578
Critical
9.8

CVE-2026-81578: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.

Added to the CISA KEV catalog:
August 31, 2026

Overview

PaperCut MF and NG contain a missing authentication flaw in the web management interface that allows an unauthenticated remote attacker to modify system configurations without credentials. Versions below 24.1.10, 25.0.13, and 26.0.5 across their respective release lines are affected. CISA notes this vulnerability can be chained with CVE-2026-82078, which extends the impact to remote code execution on the print management server.

Vulnerability details

Affected vendor
PaperCut
Affected product
NG/MF
Weakness type (CWE)
CWE-306, CWE-305

The web management interface processes requests to administrative functions before completing access validation checks, meaning backend actions execute before the server confirms the caller's identity. This is a CWE-306 (Missing Authentication for Critical Function) condition: the authentication gate exists in the code path but is reached too late, after privileged operations have already been triggered. CWE-305 reinforces this characterization, as the primary authentication mechanism is effectively bypassed rather than defeated by a secondary weakness. The result is that administrative endpoints are reachable by any network-adjacent caller without credentials.


An attacker sends crafted unauthenticated HTTP requests to administrative endpoints of the PaperCut web management interface. The Metasploit module published for this flaw targets an external user lookup function, with separate execution paths for H2 databases (version 26 branch) and Derby databases (versions 24 through 25). On its own, CVE-2026-81578 allows modification of certain system configurations. When chained with CVE-2026-82078, as CISA notes, the auth bypass serves as the entry point for full remote code execution on the PaperCut server. The only precondition is that the management interface is network-reachable from the attacker's position.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor web server access logs on the PaperCut application server for unauthenticated requests to administrative endpoints, particularly those involving external user lookup or configuration-modification functions, with no corresponding authenticated session.
  • Alert on unexpected process spawning from the PaperCut server process, particularly Java child processes or shell commands, which would indicate successful chaining with CVE-2026-82078 and active code execution.
  • Audit PaperCut system configuration change logs for modifications that cannot be correlated to an authenticated administrator session, which would indicate the auth bypass was used to alter settings.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 14, 2026

Additional hardening

  • Upgrade PaperCut MF/NG to version 24.1.10, 25.0.13, or 26.0.5 depending on the deployed release line; see the vendor advisory in References for the full version matrix.
  • Restrict network access to the PaperCut web management interface using firewall rules or network segmentation so that only authorized administrator workstations and subnets can reach the management port.
  • If the management interface cannot be patched or restricted immediately, consider taking it offline or placing it behind a VPN or reverse proxy that enforces authentication before passing requests to the application.
  • Review PaperCut system configuration and administrator audit logs for unauthorized changes made prior to patching, as the flaw permits configuration modification without leaving authenticated session records.

Key dates

Published (NVD)
August 28, 2026
Added to CISA KEV
August 31, 2026
Remediation deadline
September 14, 2026
Last updated
September 1, 2026

References

Frequently asked questions

Does CVE-2026-81578 affect my FedRAMP authorization?

If PaperCut NG/MF runs inside your authorization boundary, CVE-2026-81578 directly affects your FedRAMP authorization. CISA has listed this vulnerability in the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of September 14, 2026. An unpatched KEV within your boundary is an assessor finding. Before that date, you must either remediate it or formally document a mitigation, or your sponsoring agency will raise it.

How does Knox help me handle CVE-2026-81578?

Knox does not patch PaperCut NG/MF on your behalf. Under the FedRAMP shared-responsibility model, remediating CVE-2026-81578 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, along with Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; managing compliance posture while you do it is not something you handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment continuously for newly disclosed vulnerabilities and compliance issues, including CVE-2026-81578. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you the lead time to act before a finding becomes a formal conversation with your agency.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-81578 isn't remediated by September 14, 2026?

An unremediated CVE-2026-81578 past the September 14, 2026 deadline becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list turns a routine continuous-monitoring review into a difficult agency conversation. Closing the item out and formally documenting the remediation is what keeps your authorization clean and your agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting