THREATOPS
THREAT OPSThreat News › CVE-2026-81578 + CVE-2026-82078 | PaperCut NG/MF Authentication Bypass and Unsafe Dynamic Class Loading Vulnerabilities

CVE-2026-81578 + CVE-2026-82078 | PaperCut NG/MF Authentication Bypass and Unsafe Dynamic Class Loading Vulnerabilities

medhorizon3Published 2026-09-01

<p>PaperCut NG and PaperCut MF are affected by two vulnerabilities that can be chained to achieve unauthenticated remote code execution on the PaperCut Application Server. CVE-2026-81578, an improper access control vulnerability with a CVSS 4.0 score of 8.8 (High), allows unauthenticated remote requests to trigger certain administrative backend actions before access validation is completed…</p> <p

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://horizon3.ai/attack-research/vulnerabilities/cve-2026-81578-cve-2026-82078/