CVE-2026-81578 is a missing-authentication vulnerability in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated requests to administrative functionality can cause backend administrative actions to occur before access-validation checks complete. An unauthenticated remote attacker can thereby invoke restricted administrative functionality and modify certain PaperCut system configuration settings. The flaw can be chained with CVE-2026-82078 to obtain unauthenticated remote code execution in the PaperCut service context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This is a small, single-file Python PaperCut security-assessment tool. The primary executable, papercut.py (about 54 KB), uses requests for HTTP(S) GET/POST probing, socket connections for TCP port prefiltering, and Rich for terminal output. It exposes commands for scan, fingerprint, CVE-specific checks, batch scanning, a local lab, an exploit mode, log detection, reporting, interactive use, and self-test. The scanner fingerprints reachable user-supplied targets for PaperCut, version information, Apache Tapestry indicators, and accessible administrative/database-configuration endpoints; it evaluates detected versions against hard-coded fixed-version thresholds. It suppresses TLS verification warnings and makes requests with a PaperCut-Security-Tool user agent. The repository also contains documentation, contribution/security policies, an MIT license, and a two-package requirements file. Although the project advertises a --force-gated remote exploit mode for authentication-bypass and unsafe-class-loading CVEs, the supplied documentation explicitly characterizes remote checks as indicator-based, limits concept demonstrations to loopback hosts, and says RCE/payload execution is not implemented. Accordingly, this is best characterized as a proof-of-concept assessment/exploit-simulation tool rather than a weaponized RCE implementation. No fixed external exploit-server URL, target IP, hard-coded port, filesystem target, or registry target is visible in the supplied code; remote scan targets are runtime user input.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
217 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A CVSS 8.8 missing-authentication flaw (CWE-306) in the PaperCut NG and PaperCut MF web management interface. Crafted unauthenticated requests can trigger administrative actions and modify configuration, providing the first stage of an RCE chain.
A vulnerability in PaperCut NG/MF that was exploited to obtain remote code execution and support rapid compromise of exposed PaperCut instances.
An actively exploited PaperCut NG/MF vulnerability that is used together with CVE-2026-82078 to bypass authentication and execute arbitrary code on vulnerable instances.
A PaperCut NG/MF zero-day vulnerability that permits remote unauthenticated attackers to bypass authentication and execute arbitrary code. It was exploited in an AI-enabled campaign affecting hundreds of deployments.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.