← All CVEs NewScan detects
high

CVE-2026-82077

PaperCut MF/NG Scan-to-Fax path traversal reaching command execution on the host (CVSS 7.3)

Severity
high
Affected product
PaperCut MF/NG
Affected versions
PaperCut MF/NG ≥ 25.0.0, < 25.0.13
Affected versions
PaperCut MF/NG ≥ 26.0.0, < 26.0.5
Fixed in
PaperCut MF/NG 25.0.13
Fixed in
PaperCut MF/NG 26.0.5
Added to NewScan
2026-09-24
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the PaperCut MF/NG appliance and reports this CVE when the detected version falls inside the affected range below.

The 25.x arm. Same bulletin, same bounds and same branch split as the CVE-2026-87739 rows above - read the 25.x note there. This one is an improper limitation of a pathname in the Scan-to-Fax component, reached through crafted fax provider settings, and PaperCut is explicit that it needs an authenticated ADMINISTRATOR: it is a post-compromise escalation from the management interface to the host operating system, not an anonymous entry point, and the detail should not be read as one. It is still a row rather than a backlog line because unlike CVE-2026-14780 it is gated on VERSION ALONE - the bulletin bounds it with no feature or configuration precondition, so every install in the range is affected and the version gate is the whole truth about it.

APPLIANCE FINGERPRINT

NewScan fingerprints the PaperCut MF/NG appliance and reports this CVE when the detected version falls inside the affected range below.

The 26.x arm of CVE-2026-82077 - read the 25.x row's note.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →