Skip to main content
Vulnerability Database/CVE-2026-82077

CVE-2026-82077: PaperCut NG/MF Path Traversal Vulnerability

CVE-2026-82077 is a path traversal flaw in PaperCut NG and MF Scan-to-Fax component that enables authenticated administrators to execute arbitrary commands. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-82077 Overview

CVE-2026-82077 is a path traversal vulnerability [CWE-22] in the Scan-to-Fax component of PaperCut NG and PaperCut MF. An authenticated administrator can supply crafted fax provider settings that escape the intended directory boundary. The resulting file path manipulation enables execution of arbitrary commands on the underlying host operating system.

The issue stems from improper limitation of a pathname to a restricted directory when processing fax provider configuration input. Successful exploitation grants full command execution in the security context of the PaperCut service account.

Critical Impact

An authenticated administrator can achieve arbitrary command execution on the PaperCut server host by injecting traversal sequences into fax provider settings.

Affected Products

Discovery Timeline

  • 2026-09-24 - CVE-2026-82077 published to NVD
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-82077

Vulnerability Analysis

The Scan-to-Fax component of PaperCut NG and PaperCut MF accepts administrator-supplied fax provider settings. These settings include path values that the application uses when invoking fax provider processes. The application does not properly canonicalize or validate the supplied path.

An attacker with administrator credentials can inject traversal sequences or unexpected path components into these settings. When the Scan-to-Fax subsystem later launches the provider, the crafted path resolves to an attacker-controlled binary or command. This transforms a configuration primitive into arbitrary command execution on the PaperCut host.

Because PaperCut services often run with elevated privileges on print server infrastructure, code execution translates directly into host compromise. The Scan-to-Fax component is a documented integration point, which makes the affected code path reachable through the standard administrative interface.

Root Cause

The root cause is improper limitation of a pathname to a restricted directory [CWE-22]. The fax provider settings handler trusts administrator input as a valid path without enforcing a strict allowlist or canonical containment check. This design permits path values that reference locations outside the intended fax provider directory.

Attack Vector

Exploitation requires network access to the PaperCut administrative interface and valid administrator credentials. The attacker navigates to the Scan-to-Fax configuration, submits a fax provider setting containing traversal sequences, and triggers the code path that invokes the provider. The service then executes the attacker-referenced command in the PaperCut process context.

Verified technical details are limited to what the vendor advisory publishes. See the PaperCut Security Bulletin September 2026 for the authoritative description.

Detection Methods for CVE-2026-82077

Indicators of Compromise

  • Unexpected modifications to PaperCut Scan-to-Fax provider configuration entries in application audit logs
  • Child processes spawned by the PaperCut service that are not standard fax provider binaries
  • New or modified files under directories referenced by fax provider path settings, especially outside the expected fax provider directory
  • Outbound network connections from the PaperCut host to unknown destinations shortly after fax provider configuration changes

Detection Strategies

  • Audit PaperCut administrative activity logs for changes to fax provider settings and correlate with the identity and source IP of the administrator account
  • Monitor process creation events where the parent process is the PaperCut server or Scan-to-Fax component and the child process is a shell interpreter (cmd.exe, powershell.exe, /bin/sh, /bin/bash)
  • Alert on file path values in configuration containing traversal patterns such as ..\, ../, or absolute paths pointing outside the PaperCut installation directory

Monitoring Recommendations

  • Enable and centralize PaperCut application and admin audit logs in a SIEM for correlation with endpoint telemetry
  • Baseline the expected child process tree of the PaperCut service and alert on deviations
  • Restrict and monitor administrative logon sessions to the PaperCut console, including multi-factor authentication events

How to Mitigate CVE-2026-82077

Immediate Actions Required

  • Apply the patched PaperCut NG and PaperCut MF releases identified in the PaperCut Security Bulletin September 2026
  • Rotate credentials for all PaperCut administrator accounts and review recent administrative activity for unauthorized configuration changes
  • Restrict network access to the PaperCut administrative interface to trusted management networks only
  • Run the PaperCut service under a least-privilege account rather than a highly privileged system account

Patch Information

PaperCut has published fixed versions in the September 2026 security bulletin. Administrators should consult the PaperCut Security Bulletin September 2026 for the exact PaperCut NG and PaperCut MF versions that remediate this issue and follow the vendor upgrade procedure.

Workarounds

  • Disable the Scan-to-Fax component if it is not required by the deployment until patching is complete
  • Enforce multi-factor authentication on all PaperCut administrator accounts to reduce the risk of credential-based access
  • Place the PaperCut administrative interface behind a VPN or IP allowlist to limit exposure to authenticated attackers
bash
# Example: restrict access to the PaperCut admin interface (port 9192) using iptables
iptables -A INPUT -p tcp --dport 9192 -s 10.0.0.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 9192 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.