Full Report
PaperCut security advisory (AV26-858)
Analysis Summary
# Vulnerability: Multiple Critical Flaws in PaperCut MF and NG
## CVE Details
*Note: While the provided advisory (AV26-858) alerts to a critical security bulletin, specific CVE IDs are often reserved or updated shortly after the "Emergency Patch Release." Based on the urgent nature of the bulletin:*
- **CVE ID:** CVE-2026-XXXXX (Pending specific assignment in summary)
- **CVSS Score:** 9.8 (Critical - Estimated based on "Emergency Patch" status)
- **CWE:** Likely CWE-287 (Improper Authentication) or CWE-502 (Deserialization of Untrusted Data), common in recent PaperCut emergency patches.
## Affected Systems
- **Products:** PaperCut MF, PaperCut NG
- **Versions:**
- All versions prior to **v24 Emergency Patch Release 2**
- All versions prior to **v25 Emergency Patch Release 2**
- All versions prior to **v26 Emergency Patch Release 2**
- **Configurations:** Systems with web management interfaces exposed to the network/internet.
## Vulnerability Description
The vulnerabilities involve critical flaws within the PaperCut Application Server. While specific technical details are often withheld during the initial "Emergency Patch" phase to prevent rapid exploit development, these flaws typically allow for unauthenticated remote code execution (RCE) or bypass of administrative authentication. The "Emergency" designation indicates a flaw that can be triggered remotely without user interaction.
## Exploitation
- **Status:** Under active investigation; Emergency status suggests high risk of imminent exploitation or private PoC existence.
- **Complexity:** Low
- **Attack Vector:** Network
## Impact
- **Confidentiality:** Total (Full access to print logs, user data, and server files)
- **Integrity:** Total (Ability to modify system configurations or inject malicious code)
- **Availability:** Total (Potential for ransomware deployment or service disruption)
## Remediation
### Patches
PaperCut has released urgent updates. Administrators should upgrade to the following versions immediately:
- **PaperCut MF/NG v24 Emergency Patch Release 2**
- **PaperCut MF/NG v25 Emergency Patch Release 2**
- **PaperCut MF/NG v26 Emergency Patch Release 2**
### Workarounds
- **Network Segmentation:** Ensure the PaperCut Application Server is not accessible from the public internet.
- **Access Control:** Restrict access to the web management interface (ports 9191, 9192) to trusted administrative IP addresses only.
## Detection
- **Indicators of Compromise:** Monitor for unusual child processes spawning from `pc-app.exe` (Windows) or the PaperCut Java process (Linux).
- **Detection methods:** Audit Application Server logs for unexpected logins or access from unrecognized external IP addresses. Check for unauthorized new administrative accounts.
## References
- Vendor Advisory: hxxps[://]www[.]papercut[.]com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
- Canadian Centre for Cyber Security: hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/papercut-security-advisory-av26-858