vulnti.work

PaperCut NG/MF: PaperCut NG/MF Unsafe Reflection Vulnerability

Info Listed in CISA KEV
CVECVE-2026-82078
First seen2026-08-31 19:15 UTC
Disclosed2026-08-31 00:00 UTC
Last updated2026-08-31 19:15 UTC
Channel statusauto

Summary

PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • PaperCut:NG/MF

Sources

  • CISA KEV DATABASE

Original Links

Timeline

  1. kev_ingest CISA KEV