CVE-2026-87739
PaperCut MF/NG generates reports for an unauthenticated caller - user permissions are never evaluated (CVSS 6.9)
- Severity
- medium
- Affected product
- PaperCut MF/NG
- Affected versions
- PaperCut MF/NG ≥ 25.0.0, < 25.0.13
- Affected versions
- PaperCut MF/NG ≥ 26.0.0, < 26.0.5
- Fixed in
- PaperCut MF/NG 25.0.13
- Fixed in
- PaperCut MF/NG 26.0.5
- Added to NewScan
- 2026-09-24
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the PaperCut MF/NG appliance and reports this CVE when the detected version falls inside the affected range below.
The 25.x arm. Added 2026-09-24 (/daily-cve) from the PaperCut NG/MF Security Bulletin of 24 Sep 2026, whose 'Who is impacted' section is the source of both bounds verbatim: 'You are affected if you are running PaperCut NG/MF earlier than 26.0.5 (or 25.0.13 on the 25.x branch)'. UNLIKE CVE-2026-81578 ABOVE, THE BOUND SITS EXACTLY AT THE FIXED RELEASE and does not stop one below it: that CVE was fixed at BUILD level (24.1.9.76515) while the appliances.json fingerprint only captures the release, so its rows had to under-claim by a release; this one is fixed at RELEASE level, so `lt 25.0.13` is the advisory's own line and a patched install falls outside it exactly. Split per branch for the same reason as 81578 - a single `lt 26.0.5` would call a fully patched 25.0.13 vulnerable. The bug is a missing permission evaluation on report generation: an unauthenticated caller submits a report request and gets the report, which on a print server means user names, device names and per-user print history. IDENTIFICATION AND VERSION come from the appliances.json PaperCut row's anonymous `PaperCut MF <release> (Build <n>)` document - unchanged, no new observation source needed, which is the whole reason this was a data edit. 24.x and earlier carry NO row: the bulletin names a fixed release on the 25.x and 26.x branches only and never bounds the older ones, and this file's rule is that an unbounded 'also affected' is not a range - a 24.x install still lands on the appliance advisory observation. NOT MEASURED against a live install, the same limitation the appliances.json row records: PaperCut is licensed proprietary software with no public image, so every bound here is read off the vendor bulletin rather than off a container on loopback.
APPLIANCE FINGERPRINT
NewScan fingerprints the PaperCut MF/NG appliance and reports this CVE when the detected version falls inside the affected range below.
The 26.x arm of CVE-2026-87739 - read the 25.x row's note for the source, the branch split and why this bound sits exactly at the fixed release where CVE-2026-81578's stops one below it.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →