CVE-2026-82078
KEVPaperCut NG/MF Unsafe Reflection Vulnerability
9.4
CriticalPublished:
Last updated:
Source:eb41dac7-0af8-4f84-9f6d-0272772514f4
Analyzed
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- High
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- High
- Integrity (Subsequent)
- High
- Availability (Subsequent)
- High
Description
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.
References
eb41dac7-0af8-4f84-9f6d-0272772514f4
https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/134c704f-9b21-4f2e-91b3-4a467353bcc0
https://github.com/rapid7/metasploit-framework/pull/21842134c704f-9b21-4f2e-91b3-4a467353bcc0
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82078