An unspecified vulnerability in the application server in PaperCut MF and NG versions 18.3.8 and earlier and versions 19.0.3 and earlier allows remote attackers to execute arbitrary code via an unspecified vector.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HPapercut Mf
APPPapercut≤ 18.3.819.0.1 – 19.0.3Papercut Ng
APPPapercut≤ 18.3.819.0.1 – 19.0.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
Related vulnerabilities
CVE-2026-82078CRITICAL9.4⚠ KEVsame product
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and P...
CVE-2023-27350CRITICAL9.8⚠ KEVPL ✓same product
PaperCut MF/NG — Auth Bypass i RCE bez uwierzytelnienia (SYSTEM)
CVE-2023-39143CRITICAL9.8PL ✓same product
PaperCut NG/MF – path traversal umożliwiający RCE przez upload plików
CVE-2019-8948CRITICAL9.8PL ✓same product
Script injection w PaperCut MF i NG przez interfejs użytkownika
CVE-2026-81578HIGH8.8⚠ KEVsame product
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG...