CVE-2026-81578
PaperCut MF/NG unauthenticated management-interface access control bypass chained to code execution (CISA KEV)
- Severity
- critical
- Affected product
- PaperCut MF/NG
- Affected versions
- PaperCut MF/NG ≥ 24.0.0, < 24.1.9
- Affected versions
- PaperCut MF/NG ≥ 25.0.0, < 25.0.12
- Affected versions
- PaperCut MF/NG ≥ 26.0.0, < 26.0.4
- Fixed in
- PaperCut MF/NG 24.1.9.76515 (MF) / 24.1.9.76516 (NG)
- Fixed in
- PaperCut MF/NG 25.0.12.76509 (MF) / 25.0.12.76510 (NG)
- Fixed in
- PaperCut MF/NG 26.0.4.76507 (MF) / 26.0.4.76508 (NG)
- CISA KEV
- Listed as a known exploited vulnerability
- Added to NewScan
- 2026-09-01
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the PaperCut MF/NG appliance and reports this CVE when the detected version falls inside the affected range below.
The 24.x arm. THREE ROWS FOR ONE CVE, one per supported branch, because PaperCut ships the fix on each branch separately (MF 24.1.9.76515 / 25.0.12.76509 / 26.0.4.76507, NG one build higher in each case) - a single `lt 26.0.4` would call a fully patched 25.0.12 vulnerable. EVERY BOUND STOPS AT THE RELEASE, ONE STEP BELOW THE FIX, and the gap is deliberate: the fingerprint reads `PaperCut MF 26.0.4 (Build 76494)`, where release and build are not contiguous, so a single capture group cannot produce a build-level version to compare. An install whose release EQUALS the fixed release (24.1.9, 25.0.12, 26.0.4) therefore falls outside all three rows and degrades to the appliance advisory observation, which names this CVE and tells the operator to confirm the build - under-claiming on exactly the builds the release cannot separate, instead of a false positive on every patched install. That is the same call the CVE-2025-5777 CitrixBleed-2 row in this file made for the same reason. 23.x and earlier are absent because the advisory's coverage of them is 'possibly affected', which is not a range.
APPLIANCE FINGERPRINT
NewScan fingerprints the PaperCut MF/NG appliance and reports this CVE when the detected version falls inside the affected range below.
The 25.x arm of CVE-2026-81578 - read the 24.x row's note for why the branch is split and why the bound stops one release below the fix.
APPLIANCE FINGERPRINT
NewScan fingerprints the PaperCut MF/NG appliance and reports this CVE when the detected version falls inside the affected range below.
The 26.x arm of CVE-2026-81578, the branch the Metasploit module was tested against (MF 26.0.4.76494 - a build inside this branch but AT the fixed release, so the very build the module exploits is the one this row cannot gate; it lands on the advisory observation instead). Read the 24.x row's note for the reasoning.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →