Skip to main content
Vulnerability Database/CVE-2026-87739

CVE-2026-87739: PaperCut MF/NG Authentication Bypass

CVE-2026-87739 is an authentication bypass flaw in PaperCut MF/NG that allows remote attackers to generate reports without credentials and access sensitive data. This article covers technical details, impact, and mitigation.

Published:

CVE-2026-87739 Overview

CVE-2026-87739 is an improper authentication vulnerability in PaperCut MF and PaperCut NG print management software. The flaw allows an unauthenticated, remote attacker to trigger report generation without valid credentials. By submitting crafted report generation requests, an attacker can produce reports and access sensitive information intended for authenticated administrators.

The vulnerability is tracked as CWE-639: Authorization Bypass Through User-Controlled Key. PaperCut disclosed the issue in its September 2026 security bulletin.

Critical Impact

Remote, unauthenticated attackers can generate PaperCut reports and expose sensitive print environment data including user activity, document metadata, and organizational usage statistics.

Affected Products

  • PaperCut MF (versions covered by the September 2026 security bulletin)
  • PaperCut NG (versions covered by the September 2026 security bulletin)
  • Refer to the PaperCut Security Bulletin September 2026 for exact affected releases

Discovery Timeline

  • 2026-09-24 - CVE-2026-87739 published to the National Vulnerability Database
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-87739

Vulnerability Analysis

The vulnerability resides in the report generation functionality of PaperCut MF/NG. The application accepts and processes report generation requests without properly validating that the requester is authenticated. This authorization bypass allows any network-reachable client to invoke reporting endpoints that should be restricted to administrators.

Successful exploitation results in information disclosure. PaperCut reports typically include user identifiers, print job metadata, document names, cost data, and departmental usage patterns. Attackers can use this information to profile users, identify high-value targets, and support follow-on social engineering or reconnaissance activity.

The issue is classified under CWE-639, which covers cases where access decisions rely on a user-controlled key rather than a validated session or credential.

Root Cause

The root cause is missing or insufficient authentication checks on the report generation code path. The server processes report parameters supplied by the client and returns generated report content without confirming the caller holds a valid administrative session. Access control is applied to the user interface but not enforced at the request handler.

Attack Vector

The attack vector is network-based and requires no authentication or user interaction. An attacker with HTTP or HTTPS access to a PaperCut MF/NG server can submit report generation requests directly to the vulnerable endpoint. Exposed internet-facing PaperCut servers face the highest risk. Internal deployments remain exploitable by any user with network reachability to the server.

No verified proof-of-concept code has been published. See the PaperCut Security Bulletin September 2026 for vendor-provided technical details.

Detection Methods for CVE-2026-87739

Indicators of Compromise

  • Unexpected report files or exports generated outside of scheduled administrator activity
  • HTTP requests to PaperCut report generation endpoints originating from unauthenticated sessions or unfamiliar source IP addresses
  • Spikes in outbound traffic from the PaperCut server correlating with report retrieval
  • PaperCut application logs showing report generation events without an associated administrator login

Detection Strategies

  • Review PaperCut audit logs for report generation activity that lacks a corresponding authenticated admin session
  • Inspect web server access logs for anomalous POST or GET requests to reporting URIs from external or non-administrative networks
  • Correlate PaperCut activity with network flow data to identify unauthorized data egress

Monitoring Recommendations

  • Ingest PaperCut MF/NG application and web logs into a centralized log platform for continuous analysis
  • Alert on report generation events outside business hours or from source addresses not tied to administrator workstations
  • Monitor network perimeter devices for exposure of PaperCut administrative ports and restrict them where possible

How to Mitigate CVE-2026-87739

Immediate Actions Required

  • Apply the fixed PaperCut MF/NG version referenced in the PaperCut Security Bulletin September 2026
  • Remove direct internet exposure of PaperCut administrative and reporting interfaces
  • Review recent report generation activity for signs of unauthorized access and rotate any credentials or tokens surfaced in leaked reports

Patch Information

PaperCut has released patched versions addressing CVE-2026-87739. Consult the PaperCut Security Bulletin September 2026 for the specific fixed builds for PaperCut MF and PaperCut NG. Administrators should upgrade to the vendor-recommended version as the primary remediation.

Workarounds

  • Restrict access to the PaperCut web interface through firewall rules or reverse proxy allowlists that permit only administrator networks
  • Place PaperCut MF/NG behind a VPN or zero-trust access gateway to remove unauthenticated network exposure
  • Disable or block external access to reporting endpoints until patching is complete, using network ACLs or WAF rules
bash
# Example iptables rule restricting PaperCut admin port 9191 to an admin subnet
iptables -A INPUT -p tcp --dport 9191 -s 10.10.20.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 9191 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.