← Browse

CVE-2026-81578

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
3.3%
87.9th percentile
CISA KEV
Listed
Added 2026-08-31 · patch by 2026-09-14
Weakness / dates
CWE-305
Published 2026-08-28 · modified 2026-09-14

Description

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

Affected

papercut

References

Official: NVD · CVE.org