Vulnerability threat dossier

CVE-2023-27350

papercutpapercut mf

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.

VTP deterministic threat59.5of 100 · CVSS excluded

VTP analyst assessment

PaperCut NG/MF authentication bypass and RCE

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityCRITICAL
AI confidence95%
Public exploitation · VTP factKEV

Assessment

CVE-2023-27350 allows unauthenticated remote attackers to bypass PaperCut NG/MF access controls and execute arbitrary code. CISA KEV confirms global exploitation and known ransomware-campaign use; supplied assertions also report exploitation, zero-day characterization, and a public exploit template. These facts do not establish VTP observation.

Why it matters

  • The flaw is remotely exploitable without privileges or user interaction and carries critical system impact.
  • A public template lowers the barrier to repeatable testing or abuse, although reliability is not established.
  • KEV and attached reporting establish substantial global exploitation context.

Evidence

5 record references and 6 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The exploit template's functional reliability is not supplied.

Several press-source independence labels are unknown, so reporting should not be counted as fully independent corroboration.

Metadata names PaperCut NG 22.0.5, while attached reporting discusses all NG/MF versions and a later zero-day; precise scope and whether every report refers to this same flaw require reconciliation.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Track PaperCut NG/MF versions and fixes specifically mapped to CVE-2023-27350.

AI baseline history (8)
  1. BASELINE ASSESSED
    PaperCut NG/MF authentication bypass and RCEgpt-5.6-sol · high
  2. BASELINE ASSESSED
    PaperCut authentication bypass with unauthenticated code executiongpt-5.6-sol · high
  3. BASELINE ASSESSED
    Critical PaperCut authentication bypass with known exploitationgpt-5.6-sol · high
  4. BASELINE ASSESSED
    Critical PaperCut authentication bypass with known exploitationgpt-5.6-sol · high
  5. BASELINE ASSESSED
    PaperCut authentication bypass enabling code executiongpt-5.6-sol · high
  6. BASELINE ASSESSED
    PaperCut MF/NG improper access control enabling unauthenticated code executiongpt-5.6-sol · high
  7. BASELINE ASSESSED
    PaperCut MF/NG authentication bypass and code executiongpt-5.6-sol · high
  8. BASELINE ASSESSED
    PaperCut MF/NG authentication bypass and RCEgpt-5.6-sol · high

Previous AI priority: HIGH → current: CRITICAL. Inspect the evidence preserved for each run before treating this as a threat transition.

Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS1.00100th percentile · prediction
Evidence confidence90%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    A proof of concept is reported; functional reliability is not established.

  3. 03

    EPSS is 1.00; this is predictive context, not exploitation evidence.

  4. 04

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

RESEARCH PUBLICATIONNew technical research
EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

5publications detected
5underlying evidence chains

1 primary sources · 0 dependent secondary reports · 3 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:a4f95c36ca6e473a3d6806f7e7ec11f9a41319e150dcf738931830f0bdddad21ACTIVE
Evidence
Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
64%claim confidence
UNKNOWNreport:a4f95c36ca6e473a3d6806f7e7ec11f9a41319e150dcf738931830f0bdddad21ACTIVE
Evidence
Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:NUCLEI:8a15915ac64046879dfa4922f966118474d7af98ACTIVE
Evidence
04

Event history

Threat timeline

  1. 10:0928 Aug
    RESEARCH PUBLICATION

    New technical research

    Rapid7 Research published evidence linked to CVE-2023-27350.

  2. 16:3127 Aug
    ZERO DAY

    Zero Day

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  3. 16:3127 Aug
    EXPLOITATION REPORTED

    Exploitation Reported

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  4. 18:1724 Aug
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    ProjectDiscovery nuclei-templates published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  5. 00:0021 Apr
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

PaperCut releases second emergency patch for exploited flaws

PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...]

CVE-2023-27350CVE-2026-81578CVE-2026-82078
Separate evidence group
Original

PaperCut NG/MF Critical Zero-Day Exploited in the Wild

Overview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. At the initial time of disclosure, the vulnerability had not been assigned a CVE identifier, and PaperCut had not publicly disclosed a CVSS score, vulnerability class, authentication requirements, or the technical details of the exploit path. However on August 28, the vendor assigned CVE-2026-81578 and CVE-2026-82078 for the two vulnerabilities that make up the exploit chain. CVE ID Description CWE CVSSv4 CVE-2026-81578 Authentication Bypass CWE-306 Missing authentication for critical function. 8.8 (High) CVE-2026-82078 Unsafe Dynamic Class Loading in Database Connector CWE-470 Use of Externally-Controlled input to select classes or code ('unsafe reflection'). 9.4 (Critical) PaperCut NG and PaperCut MF are print management platforms commonly deployed within enterprise, education, and other organizational environments. Because the PaperCut Application Server provides web-accessible administrative and application functionality, organizations with servers exposed to the public internet should prioritize remediation and access restriction. PaperCut stated in its advisory that information supplied by a university customer’s security team and digital forensics and incident response team enabled its security response team to reproduce the vulnerability in PaperCut NG and PaperCut MF. On August 28, 2026 at 02:10 AEST, PaperCut released emergency patches for PaperCut NG and PaperCut MF versions 25 and 26, followed later the same day with patches for version 24. PaperCut has been targeted in the past; in 2023, CVE-2023-27350 was broadly exploited in the wild by multiple threat-actor groups, including ransomware operators. This prior history increases the urgency organizations should address this new zero-day with. PaperCut currently considers all versions of PaperCut NG and PaperCut MF potentially impacted. Customers operating internet-accessible PaperCut Application Servers should take immediate action even if no suspicious activity has been observed. On August 31, 2026, both CVE-2026-81578 and CVE-2026-82078 were added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) list of known exploited vulnerabilities (KEV), based on evidence of active exploitation. A Metasploit module is now available to validate exposure to the exploit chain. Technical overview The vulnerability is an authentication bypass that lets attackers invoke privileged PaperCut components. This can be leveraged to reconfigure an external database lookup. When this lookup is triggered, malicious SQL can be executed, resulting in remote code execution. PaperCut uses the Apache Tapestry framework, whose "complex direct" request format can identify one page to display and a different page containing the component to execute. PaperCut validates access only to the displayed page. By selecting either the public Error page or Exception page for display, an attacker can bypass authentication while invoking administrative components belonging to ConfigEditor or UserList . Additionally, the first emergency patch could be bypassed by using the Home page for display, however the newest version of the vendor patch correctly remediates this bypass. The attack uses HTTP POST requests to the following URIs (Note that the path segment with the value 1 shown below can be any value for this path segment, and the Error path segment may also be the Exception or Home path segment): /app?service=direct/1/Error/ConfigEditor/quickFindForm /app?service=direct/1/Error/ConfigEditor/$Form /app?service=direct/1/Error/UserList/$QuickFind.$Form The first two URIs provide unauthenticated access to PaperCut's configuration editor. The third can invoke a user or card search that triggers the configure

CVE-2023-27350CVE-2026-81578CVE-2026-82078
Separate evidence group
Original

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It said it's "aware of confirmed customer incidents and is treating this matter with the highest priority." An

CVE-2023-27350CVE-2026-81578CVE-2026-82078
Separate evidence group
Original

PaperCut warns of NG, MF flaw exploited in zero-day attacks

PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. [...]

CVE-2023-27350
Separate evidence group
Original

Exploit tooling coverage expanded for 51 CVEs

ProjectDiscovery nuclei-templates added or materially changed exploit-oriented artifacts covering 51 CVEs. This establishes public tooling availability; it does not establish exploitation in the wild or successful execution.

CVE-2015-7501CVE-2018-11714CVE-2018-14839CVE-2018-7282CVE-2019-1003030CVE-2020-10204CVE-2020-23575CVE-2021-44228CVE-2022-1281CVE-2023-25157CVE-2023-25826CVE-2023-27350CVE-2023-31059CVE-2023-3710CVE-2023-39143CVE-2024-33605CVE-2024-57726CVE-2025-0520CVE-2025-26399CVE-2026-0558CVE-2026-11387CVE-2026-12394CVE-2026-15826CVE-2026-19478CVE-2026-19598CVE-2026-19900CVE-2026-20896CVE-2026-21858CVE-2026-25895CVE-2026-26217CVE-2026-32255CVE-2026-35037CVE-2026-3576CVE-2026-40217CVE-2026-4060CVE-2026-41042CVE-2026-45695CVE-2026-49069CVE-2026-5032CVE-2026-52806CVE-2026-53753CVE-2026-54917CVE-2026-55224CVE-2026-56265CVE-2026-56270CVE-2026-57219CVE-2026-57827CVE-2026-61511CVE-2026-64849CVE-2026-6854CVE-2026-69084
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score59.5vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction20 / 20
Exploit availability7.5 / 15
Source independence0 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-284
CPE records
2
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.