SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-81578

CRITICAL · CVSS 9.8 EPSS 1.62% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

An improper access control vulnerability in the web management interface of PaperCut MF and PaperCut NG allows unauthenticated remote attackers to execute administrative functions without proper access validation. This can lead to unauthorized modifications of system configurations, potentially compromising the integrity and security of the affected systems. Organizations using these products should prioritize patching this vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links
External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-81578
Severity
CRITICAL
CVSS
9.8
EPSS
1.62%

Original NVD Description

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

Related CVEs

Other vulnerabilities affecting the same vendor(s)