Authentication Bypass and Remote Code Execution in PaperCut MF/NG (CVE‑2026‑81578, CVE‑2026‑82078) Enable Credential Theft in Education Organizations
What It Is — PaperCut released two critical flaws: CVE‑2026‑81578 (authentication bypass) and CVE‑2026‑82078 (remote code execution). Together they allow an unauthenticated attacker to execute commands on the print‑management server and harvest administrator credentials.
Exploitability — The Arctic Wolf Adversary Research Team has observed active exploitation in the wild, targeting schools and universities in the U.S. and Europe. Both CVEs have public PoCs and a CVSS v3.1 base score of 9.8 (Critical).
Affected Products — PaperCut MF and PaperCut NG on Windows and Linux servers (versions prior to the September 2026 security patch).
Why It Matters for Trust & Control Assurance
- Access‑control integrity – An authentication bypass directly violates the control objective of ensuring only authorized users can access privileged functions.
- Continuous evidence – Detecting anomalous command execution and credential‑theft activity requires robust logging and real‑time monitoring to provide defensible audit trails.
- Third‑party risk – Relying on unmanaged print‑management software expands the attack surface; demonstrating due‑diligence over vendor patches is a key trust signal for auditors and partners.
Recommended Actions
- Apply PaperCut’s September 2026 security update immediately.
- Verify that all print‑management servers are running a patched version; inventory any legacy instances.
- Enforce multi‑factor authentication for all PaperCut admin accounts and rotate compromised credentials.
- Enable detailed command‑execution logging and integrate logs into a SIEM for continuous monitoring.
- Review third‑party risk documentation to confirm that vendor patch management processes meet your control‑assurance requirements.
Source: The Hacker News