CVE-2026-81578 is a high-severity improper access-control vulnerability in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated requests directed at administrative functions can cause backend actions to occur before access validation has completed. This authorization-ordering flaw permits a remote unauthenticated attacker to modify certain PaperCut system configuration settings. The vulnerability can be chained with CVE-2026-82078, an unsafe dynamic class-loading flaw, to achieve unauthenticated remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A CVSS 8.8 authentication-bypass flaw in the PaperCut NG/MF web management interface. It enables unauthenticated requests to invoke backend administrative actions before access validation completes, and can be chained with CVE-2026-82078 for remote code execution.
A CVSS 8.8 improper access-control flaw in the PaperCut MF and NG web-management interface that permits unauthenticated remote requests to trigger administrative backend actions before authorization validation completes. Attackers chain it with CVE-2026-82078 to bypass authentication and obtain remote code execution.
A high-severity vulnerability affecting PaperCut NG and PaperCut MF print-management software. PaperCut reported confirmed customer incidents and active exploitation by cybercriminals.
A high-severity improper access-control/authentication-bypass vulnerability in the PaperCut MF and PaperCut NG web management interface. An unauthenticated remote attacker may cause backend administrative actions before authorization validation completes, enabling modification of certain system configurations.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.