CVE-2026-81578

Executive Summary

PaperCut MF/NG web management interface has an improper access control flaw that allows unauthenticated remote attackers to invoke administrative functions before access checks complete, enabling modification of system configurations. The vulnerability is actively exploited (CISA KEV).


Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2026-08-28T16:18:29.600 - Last Modified: 2026-09-14T00:16:56.207

[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2026-08-31)

Original Description: An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

"It is only with the heart that one can see rightly, what is essential is invisible to the eye."

— Antoine de Saint-Exupery
Source: NVD