Missing authentication in PaperCut - chained with a second flaw it reaches arbitrary code execution (CVE-2026-81578)
A missing authentication for critical function vulnerability in the print management software PaperCut NG/MF has been added to CISA's Known Exploited Vulnerabilities catalog. An unauthenticated remote attacker can modify certain system configurations.
Key facts
- CVE IDCVE-2026-81578
- Affected (vendor / product)PaperCut NG/MF
- CWECWE-306
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2026-09-14 (U.S. federal civilian agencies, BOD 22-01)
Key points
- Missing authentication for a critical function in PaperCut NG/MF lets an unauthenticated remote attacker modify certain system configurations.
- CISA's description states explicitly that it can be chained with CVE-2026-82078.
- That partner flaw manipulates configuration parameters to execute arbitrary Java bytecode.
- What looks alone like a configuration change becomes remote code execution in combination.
- Of the 1,687 KEV records this site holds as of 2026-09-02, 28 (1.7 per cent) name a chain in the description.
- The due date is fourteen days after addition; among the 1,687, twenty-one days is most common at 1,025 and fourteen days covers 269.
1Changing settings is not where it ends
What this vulnerability alone permits is modifying certain system configurations. No files are taken and no code is run. Yet CISA's description states it can be chained with another vulnerability. That other flaw, CVE-2026-82078, manipulates configuration parameters to execute Java bytecode.
- 1The way inCertain system configurations can be modified without authentication (this flaw)
- 2The footholdThe modified configuration parameters become input to the next flaw
- 3ExecutionUnsafe reflection executes arbitrary Java bytecode
- 4ReachIt runs in the security context of the PaperCut server process
What looks alone like a configuration change becomes remote code execution in combination. Assessing severity one entry at a time misses this shape.
2Twenty-eight records name a chain
CISA names the partner in a chain inside the description for 28 of 1,687 records. Conversely, combinations not named cannot be read from the records. Attackers see reachable paths rather than individual flaws, so defenders have to think in combinations too.
3Fourteen days to remediate
The due date is set fourteen days after addition. Of the 1,687 records this site holds as of 2026-09-02, 269 carry a fourteen-day deadline, 1,025 carry twenty-one days - the most common - and 86 carry three days. The length varies with how far exploitation has spread and how hard the fix is.
Why it matters
Print management servers are reachable from many endpoints inside an organisation and tend to fall down the update queue. That a flaw limited to configuration change becomes code execution when combined with another in the same product exposes the weakness of prioritising by severity score alone. Where the partner in a chain is named, closing both at once is the judgement required.
FAQ
What can this flaw do on its own?
Why does chaining matter?
What is the deadline?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).