This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to exploit this.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HApple macOS
OSAppleall versionsLinux Kernel
OSLinuxall versionsMicrosoft Windows
OSMicrosoftall versionsPapercut Mf
APPPapercut23.0.1 – 23.0.7 (excl.)< 20.1.1021.0.0 – 21.2.14 (excl.)22.0.0 – 22.1.5 (excl.)Papercut Ng
APPPapercut23.0.1 – 23.0.7 (excl.)22.0.0 – 22.1.5 (excl.)21.0.0 – 21.2.14 (excl.)< 20.1.10
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
Related vulnerabilities
CVE-2026-82078CRITICAL9.4⚠ KEVsame product
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and P...
CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product
Pominięcie uwierzytelniania w Screen Sharing na macOS
CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu