PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMicrosoft Windows
OSMicrosoftall versionsPapercut Mf
APPPapercut< 22.1.3Papercut Ng
APPPapercut< 22.1.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEPath Traversal
Related vulnerabilities
CVE-2026-82078CRITICAL9.4⚠ KEVsame product
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and P...
CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
CVE-2024-7262CRITICAL9.3⚠ KEVPL ✓same product
Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows