DIRAS TAKE
Urgent: CISA added this issue to its Known Exploited Vulnerabilities catalog with a remediation deadline, so prioritize updates or mitigations immediately; the flaw lets high-privilege users load arbitrary classes on the server. Apply vendor updates or follow vendor mitigation instructions without delay.
What is CVE-2026-82078?
Authenticated users who can change system configuration can execute arbitrary Java bytecode in PaperCut NG/MF, allowing remote code execution against the server process. CVE-2026-82078 affects PaperCut NG/MF versions before 24.1.10 (24.x), versions 25.0.0 through before 25.0.13 (25.x), and versions 26.0.0 through before 26.0.5 (26.x). An attacker needs the ability to manipulate application configuration parameters (high privilege within the product) to exploit the unsafe dynamic class loading behavior.
Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Which versions of PaperCut NG/MF are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 24.x | before 24.1.10 | 24.1.10 |
| 25.x | 25.0.0 – before 25.0.13 | 25.0.13 |
| 26.x | 26.0.0 – before 26.0.5 | 26.0.5 |
Is CVE-2026-82078 being exploited?
CISA added CVE-2026-82078 to the Known Exploited Vulnerabilities catalog on 2026-08-31, and U.S. federal civilian agencies must apply mitigations or fixes by 2026-09-14.
How to fix CVE-2026-82078
- Upgrade PaperCut NG/MF to a fixed release: 24.1.10, 25.0.13, or 26.0.5 as appropriate for your branch.
- If you cannot immediately upgrade, restrict access to the PaperCut administrative interface and configuration files from untrusted networks.
- Follow PaperCut vendor guidance for mitigating unsafe class loading and validate configuration values against an approved list where possible.
- Monitor server logs and integrity of application classpath for unexpected classes or configuration changes.
Frequently asked questions
Is CVE-2026-82078 being actively exploited?
CISA added CVE-2026-82078 to its Known Exploited Vulnerabilities catalog on 2026-08-31; U.S. federal civilian agencies are required to apply mitigations or fixes by 2026-09-14.
Which PaperCut NG/MF versions are affected by CVE-2026-82078?
PaperCut NG/MF versions before 24.1.10 (24.x), versions 25.0.0 through before 25.0.13 (25.x), and versions 26.0.0 through before 26.0.5 (26.x) are affected.
Is there a patch for CVE-2026-82078?
Yes. PaperCut released fixed versions: 24.1.10, 25.0.13, and 26.0.5; upgrade to the appropriate fixed release for your branch.
Does CVE-2026-82078 require authentication?
Exploitation requires the ability to manipulate system configuration parameters, which implies a high-privilege account or equivalent access within the PaperCut NG/MF product.
References
- nvd.nist.gov/vuln/detail/CVE-2026-82078
- cve.org/CVERecord?id=CVE-2026-82078
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82078
- papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory
- All PaperCut CVEs on CVE Radar
- CVEs published in September 2026