Impact of the vulnerabilities CVE-2026-82078 and CVE-2026-81578 on our products
The security team at our software partner, PaperCut, is currently investigating active exploitation of a security vulnerability affecting the PaperCut NG and PaperCut MF software solutions.
We would like to take this opportunity to inform you about the vulnerabilities CVE-2026-82078 and CVE-2026-81578, their impact, and the steps you should take.
I. Summary
- Unsafe Dynamic Class Loading in Database Connector (CVE-2026-82078): An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. Impact: If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. For more information, see CVE-2026-82078.
- Authentication Bypass (CVE-2026-81578): An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. Impact: This allows an unauthenticated remote attacker to modify certain system configurations. For more information, see CVE-2026-81578.
II. Measures
If you are a TA or UTAX customer using the PaperCut MF solution, you should take corrective action as soon as possible. To do so, please follow the instructions in PaperCut’s security advisory: URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026). In addition to guidance on immediate actions, you will find an emergency patch and the latest information on this issue.