CVE Details

CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability
Published: 2026-08-28 CVSS: 9.4 CRITICAL Product: PaperCut NG/MF Due Date: 2026-09-11

PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 9.4
  • Severity: CRITICAL
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

SSVC

  • Exploitation: poc
  • Automatable: no
  • Technical Impact: total

References

Show Raw Data
Key Remaining Key Value
dataType CVE_RECORD
dataVersion 5.2
cveMetadata > cveId CVE-2026-82078
cveMetadata > assignerOrgId eb41dac7-0af8-4f84-9f6d-0272772514f4
cveMetadata > state PUBLISHED
cveMetadata > assignerShortName PaperCut
cveMetadata > dateReserved 2026-08-28T00:13:25.684Z
cveMetadata > datePublished 2026-08-28T11:45:25.388Z
cveMetadata > dateUpdated 2026-08-31T14:58:23.620Z
containers > cna > providerMetadata > orgId eb41dac7-0af8-4f84-9f6d-0272772514f4
containers > cna > providerMetadata > shortName PaperCut
containers > cna > providerMetadata > dateUpdated 2026-08-28T11:45:25.388Z
containers > cna > title PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > cweId CWE-470
containers > cna > problemTypes > 0 > descriptions > 0 > description CWE-470 Use of Externally-Controlled input to select classes or code ('unsafe reflection')
containers > cna > problemTypes > 0 > descriptions > 0 > type CWE
containers > cna > affected > 0 > vendor PaperCut
containers > cna > affected > 0 > product PaperCut MF/NG
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > affected > 0 > versions > 0 > version 0
containers > cna > affected > 0 > versions > 0 > lessThan 24.1.10, 25.0.13, 26.0.5
containers > cna > affected > 0 > versions > 0 > versionType semver
containers > cna > affected > 0 > defaultStatus unaffected
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.
containers > cna > descriptions > 0 > supportingMedia > 0 > type text/html
containers > cna > descriptions > 0 > supportingMedia > 0 > base64 False
containers > cna > descriptions > 0 > supportingMedia > 0 > value <p>An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.</p>
containers > cna > references > 0 > url https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
containers > cna > metrics > 0 > format CVSS
containers > cna > metrics > 0 > scenarios > 0 > lang en
containers > cna > metrics > 0 > scenarios > 0 > value GENERAL
containers > cna > metrics > 0 > cvssV4_0 > attackVector NETWORK
containers > cna > metrics > 0 > cvssV4_0 > attackComplexity LOW
containers > cna > metrics > 0 > cvssV4_0 > attackRequirements NONE
containers > cna > metrics > 0 > cvssV4_0 > privilegesRequired HIGH
containers > cna > metrics > 0 > cvssV4_0 > userInteraction NONE
containers > cna > metrics > 0 > cvssV4_0 > vulnConfidentialityImpact HIGH
containers > cna > metrics > 0 > cvssV4_0 > subConfidentialityImpact HIGH
containers > cna > metrics > 0 > cvssV4_0 > vulnIntegrityImpact HIGH
containers > cna > metrics > 0 > cvssV4_0 > subIntegrityImpact HIGH
containers > cna > metrics > 0 > cvssV4_0 > vulnAvailabilityImpact HIGH
containers > cna > metrics > 0 > cvssV4_0 > subAvailabilityImpact HIGH
containers > cna > metrics > 0 > cvssV4_0 > exploitMaturity NOT_DEFINED
containers > cna > metrics > 0 > cvssV4_0 > Safety NOT_DEFINED
containers > cna > metrics > 0 > cvssV4_0 > Automatable NOT_DEFINED
containers > cna > metrics > 0 > cvssV4_0 > Recovery NOT_DEFINED
containers > cna > metrics > 0 > cvssV4_0 > valueDensity NOT_DEFINED
containers > cna > metrics > 0 > cvssV4_0 > vulnerabilityResponseEffort NOT_DEFINED
containers > cna > metrics > 0 > cvssV4_0 > providerUrgency NOT_DEFINED
containers > cna > metrics > 0 > cvssV4_0 > version 4.0
containers > cna > metrics > 0 > cvssV4_0 > baseSeverity CRITICAL
containers > cna > metrics > 0 > cvssV4_0 > baseScore 9.4
containers > cna > metrics > 0 > cvssV4_0 > vectorString CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
containers > cna > source > discovery UNKNOWN
containers > cna > x_generator > engine Vulnogram 1.0.5
containers > adp > 0 > references > 0 > url https://github.com/rapid7/metasploit-framework/pull/21842
containers > adp > 0 > references > 0 > tags > 0 exploit
containers > adp > 0 > references > 1 > name CISA KEV
containers > adp > 0 > references > 1 > tags > 0 government-resource
containers > adp > 0 > references > 1 > url https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82078
containers > adp > 0 > metrics > 0 > other > type ssvc
containers > adp > 0 > metrics > 0 > other > content > timestamp 2026-08-31T12:33:45.803363Z
containers > adp > 0 > metrics > 0 > other > content > id CVE-2026-82078
containers > adp > 0 > metrics > 0 > other > content > options > 0 > Exploitation poc
containers > adp > 0 > metrics > 0 > other > content > options > 1 > Automatable no
containers > adp > 0 > metrics > 0 > other > content > options > 2 > Technical Impact total
containers > adp > 0 > metrics > 0 > other > content > role CISA Coordinator
containers > adp > 0 > metrics > 0 > other > content > version 2.0.3
containers > adp > 0 > metrics > 1 > other > type kev
containers > adp > 0 > metrics > 1 > other > content > dateAdded 2026-08-28
containers > adp > 0 > metrics > 1 > other > content > reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82078
containers > adp > 0 > title CISA ADP Vulnrichment
containers > adp > 0 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 0 > providerMetadata > shortName CISA-ADP
containers > adp > 0 > providerMetadata > dateUpdated 2026-08-31T14:58:23.620Z
containers > adp > 0 > timeline > 0 > time 2026-08-28T00:00:00.000Z
containers > adp > 0 > timeline > 0 > lang en
containers > adp > 0 > timeline > 0 > value CVE-2026-82078 added to CISA KEV