CVE-2026-87739 Overview
CVE-2026-87739 is an improper authentication vulnerability in PaperCut MF and PaperCut NG print management software. The flaw allows an unauthenticated, remote attacker to trigger report generation without valid credentials. By submitting crafted report generation requests, an attacker can produce reports and access sensitive information intended for authenticated administrators.
The vulnerability is tracked as CWE-639: Authorization Bypass Through User-Controlled Key. PaperCut disclosed the issue in its September 2026 security bulletin.
Critical Impact
Remote, unauthenticated attackers can generate PaperCut reports and expose sensitive print environment data including user activity, document metadata, and organizational usage statistics.
Affected Products
- PaperCut MF (versions covered by the September 2026 security bulletin)
- PaperCut NG (versions covered by the September 2026 security bulletin)
- Refer to the PaperCut Security Bulletin September 2026 for exact affected releases
Discovery Timeline
- 2026-09-24 - CVE-2026-87739 published to the National Vulnerability Database
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2026-87739
Vulnerability Analysis
The vulnerability resides in the report generation functionality of PaperCut MF/NG. The application accepts and processes report generation requests without properly validating that the requester is authenticated. This authorization bypass allows any network-reachable client to invoke reporting endpoints that should be restricted to administrators.
Successful exploitation results in information disclosure. PaperCut reports typically include user identifiers, print job metadata, document names, cost data, and departmental usage patterns. Attackers can use this information to profile users, identify high-value targets, and support follow-on social engineering or reconnaissance activity.
The issue is classified under CWE-639, which covers cases where access decisions rely on a user-controlled key rather than a validated session or credential.
Root Cause
The root cause is missing or insufficient authentication checks on the report generation code path. The server processes report parameters supplied by the client and returns generated report content without confirming the caller holds a valid administrative session. Access control is applied to the user interface but not enforced at the request handler.
Attack Vector
The attack vector is network-based and requires no authentication or user interaction. An attacker with HTTP or HTTPS access to a PaperCut MF/NG server can submit report generation requests directly to the vulnerable endpoint. Exposed internet-facing PaperCut servers face the highest risk. Internal deployments remain exploitable by any user with network reachability to the server.
No verified proof-of-concept code has been published. See the PaperCut Security Bulletin September 2026 for vendor-provided technical details.
Detection Methods for CVE-2026-87739
Indicators of Compromise
- Unexpected report files or exports generated outside of scheduled administrator activity
- HTTP requests to PaperCut report generation endpoints originating from unauthenticated sessions or unfamiliar source IP addresses
- Spikes in outbound traffic from the PaperCut server correlating with report retrieval
- PaperCut application logs showing report generation events without an associated administrator login
Detection Strategies
- Review PaperCut audit logs for report generation activity that lacks a corresponding authenticated admin session
- Inspect web server access logs for anomalous POST or GET requests to reporting URIs from external or non-administrative networks
- Correlate PaperCut activity with network flow data to identify unauthorized data egress
Monitoring Recommendations
- Ingest PaperCut MF/NG application and web logs into a centralized log platform for continuous analysis
- Alert on report generation events outside business hours or from source addresses not tied to administrator workstations
- Monitor network perimeter devices for exposure of PaperCut administrative ports and restrict them where possible
How to Mitigate CVE-2026-87739
Immediate Actions Required
- Apply the fixed PaperCut MF/NG version referenced in the PaperCut Security Bulletin September 2026
- Remove direct internet exposure of PaperCut administrative and reporting interfaces
- Review recent report generation activity for signs of unauthorized access and rotate any credentials or tokens surfaced in leaked reports
Patch Information
PaperCut has released patched versions addressing CVE-2026-87739. Consult the PaperCut Security Bulletin September 2026 for the specific fixed builds for PaperCut MF and PaperCut NG. Administrators should upgrade to the vendor-recommended version as the primary remediation.
Workarounds
- Restrict access to the PaperCut web interface through firewall rules or reverse proxy allowlists that permit only administrator networks
- Place PaperCut MF/NG behind a VPN or zero-trust access gateway to remove unauthenticated network exposure
- Disable or block external access to reporting endpoints until patching is complete, using network ACLs or WAF rules
# Example iptables rule restricting PaperCut admin port 9191 to an admin subnet
iptables -A INPUT -p tcp --dport 9191 -s 10.10.20.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 9191 -j DROP
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
