CVE-2026-82077
PaperCut MF/NG Scan-to-Fax path traversal reaching command execution on the host (CVSS 7.3)
- Severity
- high
- Affected product
- PaperCut MF/NG
- Affected versions
- PaperCut MF/NG ≥ 25.0.0, < 25.0.13
- Affected versions
- PaperCut MF/NG ≥ 26.0.0, < 26.0.5
- Fixed in
- PaperCut MF/NG 25.0.13
- Fixed in
- PaperCut MF/NG 26.0.5
- Added to NewScan
- 2026-09-24
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the PaperCut MF/NG appliance and reports this CVE when the detected version falls inside the affected range below.
The 25.x arm. Same bulletin, same bounds and same branch split as the CVE-2026-87739 rows above - read the 25.x note there. This one is an improper limitation of a pathname in the Scan-to-Fax component, reached through crafted fax provider settings, and PaperCut is explicit that it needs an authenticated ADMINISTRATOR: it is a post-compromise escalation from the management interface to the host operating system, not an anonymous entry point, and the detail should not be read as one. It is still a row rather than a backlog line because unlike CVE-2026-14780 it is gated on VERSION ALONE - the bulletin bounds it with no feature or configuration precondition, so every install in the range is affected and the version gate is the whole truth about it.
APPLIANCE FINGERPRINT
NewScan fingerprints the PaperCut MF/NG appliance and reports this CVE when the detected version falls inside the affected range below.
The 26.x arm of CVE-2026-82077 - read the 25.x row's note.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →