CVE-2026-87739
PaperCut MF/NG: User permissions are not evaluated on report generation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and gain unauthorized access to sensitive information.
| CWE | CWE-639 |
| Vendor | papercut |
| Product | papercut ng/mf |
| Published | Sep 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for papercut papercut ng/mf
Be the first to know when new unknown vulnerabilities affecting papercut papercut ng/mf are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
PaperCut / PaperCut NG/MF
0 < 25.0.13 26.0.0 < 26.0.5