CVE-2026-82077
PaperCut NG/MF: Remote Code Execution via Scan2Fax
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings.
| CWE | CWE-22 CWE-78 |
| Vendor | papercut |
| Product | papercut ng/mf |
| Published | Sep 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for papercut papercut ng/mf
Be the first to know when new unknown vulnerabilities affecting papercut papercut ng/mf are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
PaperCut / PaperCut NG/MF
0 < 25.0.13 26.0.0 < 26.0.5
References
Credits
Piotr Bazydlo (@chudyPB) of watchTowr