Active Exploitation of Pre‑Authentication RCE in PaperCut Print Management (CVE‑2026‑81578 & CVE‑2026‑82078)
What Happened – Researchers at Huntress confirmed that a pre‑authentication remote code execution flaw (CVE‑2026‑81578) in PaperCut NG servers is being actively probed and exploited. A second flaw (CVE‑2026‑82078) can be chained to load arbitrary Java classes, giving an attacker command‑line access without logging in.
Why It Matters for Trust & Control Assurance
- The attack bypasses normal authorization checks, directly testing the access‑control control objective that underpins many frameworks (e.g., NIST CSF 2.0).
- Continuous evidence of patch status and exploit detection is essential to demonstrate due‑diligence in audit‑ready environments.
- The ACCESS_CONTROLS capability helps organizations surface unpatched assets, enforce remediation workflows, and retain defensible logs of remediation actions.
Who Is Affected – Schools, hospitals, and office environments that run PaperCut print‑management servers worldwide.
Recommended Actions
- Verify your PaperCut version; upgrade immediately to the patched release (≥ 25.0.12).
- Deploy a continuous patch‑management feed that flags CVE‑2026‑81578/82078 across all managed endpoints.
- Enable detailed request‑logging and monitor for anomalous “page‑display vs. action” requests.
- Conduct a short‑term audit of authorization logic in custom integrations.
Source: Security Affairs
Technical Notes – The vulnerability stems from an authorization mistake where the server validates the displayed page rather than the action executed. Exploitation drops a malicious Java class into the installation directory, runs commands (e.g., whoami, ver, tasklist), and deletes its own logs. No secondary malware or C2 traffic was observed.