criticalZero-Day

PaperCut NG/MF Chained Authentication Bypass and Remote Code Execution

First seen Aug 29, 2026 · Updated Aug 29, 2026 · CVSS 9.8

papercutrceauthentication-bypassunauthenticated-rceprint-managementexploit-chainpatch-now

Attackers are actively chaining two vulnerabilities in PaperCut NG and MF print management software to achieve unauthenticated remote code execution. PaperCut has released an emergency patch with additional hardening after confirming exploitation in the wild. Organizations running unpatched PaperCut servers face full server compromise with no authentication required.

Technical Analysis

The exploit chain allows an unauthenticated attacker to manipulate PaperCut's trusted configuration settings, ultimately enabling execution of arbitrary Java code within the application context. This mirrors prior PaperCut RCE patterns (e.g., CVE-2023-27350) where attackers abused the SetupCompleted and administrative configuration endpoints to bypass authentication checks and reach code-execution-capable functionality. Given PaperCut's Java-based architecture, successful exploitation typically grants attackers the ability to spawn system shells, deploy web shells, or drop follow-on payloads such as ransomware precursors or remote access tools. The lack of authentication requirement significantly lowers the exploitation barrier, making mass scanning and automated exploitation likely once technical details circulate. If PaperCut servers are deployed on infrastructure that also hosts or is network-adjacent to AI agent orchestration systems, RAG pipelines, or agent tool-execution environments, successful RCE could allow attackers to pivot into those systems, harvest API keys or credentials used by agents, or tamper with agent configurations and tool integrations.

Affected Systems

PaperCut NG and PaperCut MF (specific vulnerable versions pending full disclosure; organizations should assume all versions prior to the emergency patch released around August 2026 are affected); Windows and Linux server deployments of PaperCut administration consoles exposed to network access.

Indicators of Compromise

  • No specific hashes, IPs, or domains disclosed in source reporting at time of analysis; monitor PaperCut admin console logs for unauthorized configuration changes, unexpected SetupCompleted flag modifications, and anomalous Java process spawning from the PaperCut service account.

Remediation Steps

  1. 1

    Apply Emergency Patch

    Immediately update PaperCut NG and MF to the latest patched version released by PaperCut in response to this vulnerability chain.

  2. 2

    Restrict Network Access

    Limit access to the PaperCut administration console (typically ports 9191/9192) to trusted internal networks only; do not expose administration interfaces to the public internet.

  3. 3

    Audit Configuration Changes

    Review PaperCut server logs for unauthorized changes to trusted configuration settings, especially those related to setup completion status and external authentication providers.

  4. 4

    Monitor for Post-Exploitation Activity

    Inspect systems running PaperCut for unexpected child processes, web shells, or lateral movement indicators originating from the PaperCut service account.

  5. 5

    Segment Print Infrastructure

    Isolate print management servers from segments hosting sensitive systems, including any AI agent orchestration or credential management infrastructure, to limit blast radius from a potential compromise.

Industries Most Exposed

educationhealthcaregovernmentmanufacturingretailprofessional-services

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.