PaperCut NG/MF Authentication Bypass and Unsafe Dynamic Class Loading Remote Code Execution Vulnerabilities (CVE-2026-81578, CVE-2026-82078).

Release Date: 2nd  September 2026

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that operate PaperCut NG or PaperCut MF print management software, including schools, hospitals, and government or office IT environments. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-81578 and CVE-2026-82078 are two critical vulnerabilities in PaperCut MF and PaperCut NG that CERTVU is addressing together because they share the same fix and are being actively chained by attackers.

CVE-2026-81578 is an authentication bypass in the web management interface: under specific conditions, an unauthenticated remote attacker can send requests targeting administrative functions that trigger backend actions before access validation completes. 

CVE-2026-82078 is a separate flaw in PaperCut's database connection utilities, caused by unsafe dynamic loading of Java classes, that lets an attacker who can influence the class reference cause PaperCut to load and execute arbitrary Java code.

Reference

  1. https://www.papercut.com/kb/Main/PC-CVE-2026-81578
  2. https://www.papercut.com/kb/Main/PC-CVE-2026-82078
  3. https://www.cve.org/CVERecord?id=CVE-2026-81578 
  4. https://www.cve.org/CVERecord?id=CVE-2026-82078 
  5. https://www.cisa.gov/known-exploited-vulnerabilities-catalog