High Known exploited (KEV) Ransomware use CVE-2023-27351

Authentication Bypass in PaperCut NG/MF (CVE-2023-27351)

PaperCut NG/MF Added to KEV Apr 20, 2026 Federal remediation due 2026-05-04

PaperCut NG/MF, a print management product, contains a flaw that may allow authentication (the identity-verification step) to be bypassed, potentially letting an attacker reach administrative functions without a valid login.

Key facts

  • CVE IDCVE-2023-27351
  • CVSS base score7.5 HIGH
  • CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Affected (vendor / product)PaperCut NG/MF
  • CWECWE-287
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2026-05-04 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Affects PaperCut NG/MF print management software through an improper authentication flaw that may allow the identity check to be bypassed.
  • The KEV record states authentication may be bypassed via the SecurityRequestFilter class, potentially leading to unauthorized access to administrative functions.
  • Listed by CISA in its Known Exploited Vulnerabilities (KEV) catalog (added 2026-04-20, remediation due 2026-05-04).
  • Exploitation by ransomware is confirmed, and the widely deployed management server is a likely target as an initial foothold.
  • Official NVD severity is CVSS 7.5 (HIGH); remediation is to apply vendor mitigations, follow BOD 22-01, or discontinue use if mitigation is not possible.
  • A management server inside the organisation is hard to take down and falls behind on updates, making it the foothold after entry.

1What bypassing authentication allows

Authentication is the process of confirming that a user is who they claim to be, so that only authorized people can operate a system. This issue is classified as improper authentication, meaning that check is not carried out properly and can be bypassed. According to the KEV record, affected installations may have authentication bypassed via the SecurityRequestFilter class.

The heart of the problem is that a widely deployed management server could be operated without going through a valid login.

2Where print infrastructure sits on the network

PaperCut NG/MF handles print accounting, billing, and usage control, giving it an important position inside an organization's network. CISA has listed this vulnerability in its Known Exploited Vulnerabilities (KEV) catalog and further notes that exploitation by ransomware (an attack that encrypts data and demands a ransom) has been confirmed.

A management server running across many organizations is a classic target used as an initial foothold for intrusion.

3A CVSS score of 7.5

The official NVD severity rating is a CVSS base score of 7.5 (HIGH, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). For remediation, CISA directs organizations to apply mitigations per vendor instructions, follow the U.S. federal directive BOD 22-01, and discontinue use of the product if mitigations are not available. The KEV-added date is 2026-04-20 and the remediation due date is 2026-05-04.

4Assets visible from outside, and management servers inside

A server handling print accounting, charging and usage control holds an important place inside the network. Attention as a target, though, does not reach it the way it reaches an internet-facing server.

An internet-facing serverA management server inside the organisation
Recognised as a targetSits in the background, doing printing or asset management
Updates are given priorityHard to take down, so updates fall behind
Targeted as the entranceTargeted as the foothold after entry
Reviewing exposure is the countermeasureBeing internal is not a reason to feel safe

CISA lists the vulnerability in the KEV catalog and further records confirmed use in ransomware. A management server running in many organisations is the textbook foothold. Being classified as improper authentication that can be bypassed means the management functions can be reached without going through a legitimate login.

Why it matters

Print management servers sit inside an organization's network and connect to many users and devices, so a successful authentication bypass could allow unauthorized access to administrative functions. Because exploitation by ransomware has been confirmed, there is a recognized risk of the flaw being used as an initial foothold for intrusion. CISA has set a remediation due date of 2026-05-04, indicating a high priority for response.

FAQ

What is PaperCut NG/MF?
It is a print management server widely used by businesses, schools, and government bodies to handle print accounting, billing, and usage control.
How severe is this vulnerability?
The official NVD rating is a CVSS base score of 7.5 (HIGH) (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
What does CISA require organizations to do?
Apply mitigations per vendor instructions, follow BOD 22-01, or discontinue use if mitigations are unavailable, with a remediation due date of 2026-05-04.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#CISA KEV#PaperCut#authentication bypass#print management#ransomware#CVE-2023-27351#vulnerability
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.