Ethical Hacking News
A recently discovered vulnerability in PaperCut's software allows attackers to execute arbitrary code without authentication, putting organizations that use the software at risk. To protect themselves, organizations are advised to remove public exposure immediately and apply the patch as soon as possible. The attack vector involves chaining two separate security flaws to bypass authentication and gain remote code execution on affected instances. Organizations must take immediate action to patch their systems and restrict access to the PaperCut web management interface to prevent further exploitation.
Attacks exploiting two security flaws in PaperCut NG and MF software have been discovered by researchers at Huntress. A vulnerability in the PaperCut NG and MF software allows attackers to execute arbitrary code without authentication. The vulnerabilities, CVE-2026-82078 and CVE-2026-81578, can be chained together to bypass authentication and gain remote code execution. The attack vector involves deploying a Java .class file to fingerprint the machine and obtain sensitive information. Organizations with PaperCut NG and MF in their environment are advised to remove public exposure and apply the patch as soon as possible. Restricting PaperCut Application Server web access to trusted IP addresses or placing it behind a VPN is recommended.
PaperCut, a software suite used to manage and monitor printing and copying devices, has been exploited by attackers to execute arbitrary code without authentication. This vulnerability, which has been discovered by researchers at Huntress, takes advantage of two separate security flaws in the PaperCut NG and MF software, allowing malicious actors to gain remote control over the application's trusted configuration.
According to Huntress researchers John Hammond and Andrew Brandt, the first vulnerability, CVE-2026-82078, is a dynamic class loading vulnerability that allows an attacker to instantiate database driver classes based on configurable driver names without validating against an allowlist of approved drivers. This vulnerability can be exploited by sending a specifically crafted request to the application, which can then be used to make changes to the server configuration and ultimately execute arbitrary Java code.
The second vulnerability, CVE-2026-81578, is an improper access control vulnerability that allows an attacker to bypass authentication and gain access to administrative functions in the PaperCut web management interface. This vulnerability can be exploited by sending a request to the application's administrative functions, which can then be used to trigger backend actions prior to the completion of access validation checks.
Researchers at Huntress have discovered that attackers are chaining together both vulnerabilities to bypass authentication and gain remote code execution on affected instances. This allows the attackers to execute arbitrary code on the targeted server, which can be used to determine the user account and operating system of the system administrator.
The attack vector used by the attackers involves deploying a Java .class file that is operating system agnostic and can run commands under either Linux or Windows systems to fingerprint the machine and obtain a directory listing of files stored on the computer. The data is written to a file named "Udydn.out" in a "/data/content/" path relative to the program's installation directory.
Once the .class file is executed, it deletes the "Udydn.out" file, the server's "server.log" file, and a "/data/internal/derby.log" file. This allows the attackers to cover their tracks and avoid detection.
Organizations that have PaperCut NG and MF in their environment are advised to remove public exposure immediately and apply the patch as soon as possible. It is also recommended to restrict PaperCut Application Server web access to trusted IP addresses or place it behind a VPN or another controlled administrative path.
"PaperCut is a prime target for attackers of every motivation, as not only is it an internet-facing pivot into a corporate environment, but it is a sensitive information treasure trove if printed documents can be stored and exfiltrated," said Jake Knott, head of threat intelligence at watchTowr.
"The vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's process," said John Hammond, senior principal security researcher at Huntress.
"It is essential for organizations to take immediate action to patch their systems and restrict access to the PaperCut web management interface to prevent further exploitation," added Andrew Brandt, researcher at Huntress.
In conclusion, the exploitation of PaperCut's security flaws highlights the importance of keeping software up to date and taking steps to secure internet-facing devices. It also emphasizes the need for organizations to have robust security controls in place to prevent unauthorized access to sensitive information.
Related Information:
https://www.ethicalhackingnews.com/articles/Chaining-Vulnerabilities-The-Exploitation-of-PaperCuts-Security-Flaws-ehn.shtml
https://thehackernews.com/2026/08/attackers-chain-two-papercut-flaws-to.html
https://nvd.nist.gov/vuln/detail/CVE-2026-82078
https://www.cvedetails.com/cve/CVE-2026-82078/
https://nvd.nist.gov/vuln/detail/CVE-2026-81578
https://www.cvedetails.com/cve/CVE-2026-81578/
Published: Sat Aug 29 17:22:52 2026 by llama3.2 3B Q4_K_M