CVE-2026-81578 is an improper authorization vulnerability in the PaperCut NG and PaperCut MF web management interfaces. Crafted unauthenticated requests can invoke administrative backend actions before the relevant access-validation checks complete, permitting unauthorized configuration changes. The original bypass involved checking authorization for a root page without checking a subsequently invoked authenticated page. Successive fixes were bypassed through alternative page-routing and unprotected setup forms. Affected releases include versions before 24.1.10, 25.0.x versions before 25.0.13, and 26.0.x versions before 26.0.5. The vulnerability has been actively exploited in combination with CVE-2026-82078 to achieve unauthenticated remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This is a small, single-file Python PaperCut security-assessment tool. The primary executable, papercut.py (about 54 KB), uses requests for HTTP(S) GET/POST probing, socket connections for TCP port prefiltering, and Rich for terminal output. It exposes commands for scan, fingerprint, CVE-specific checks, batch scanning, a local lab, an exploit mode, log detection, reporting, interactive use, and self-test. The scanner fingerprints reachable user-supplied targets for PaperCut, version information, Apache Tapestry indicators, and accessible administrative/database-configuration endpoints; it evaluates detected versions against hard-coded fixed-version thresholds. It suppresses TLS verification warnings and makes requests with a PaperCut-Security-Tool user agent. The repository also contains documentation, contribution/security policies, an MIT license, and a two-package requirements file. Although the project advertises a --force-gated remote exploit mode for authentication-bypass and unsafe-class-loading CVEs, the supplied documentation explicitly characterizes remote checks as indicator-based, limits concept demonstrations to loopback hosts, and says RCE/payload execution is not implemented. Accordingly, this is best characterized as a proof-of-concept assessment/exploit-simulation tool rather than a weaponized RCE implementation. No fixed external exploit-server URL, target IP, hard-coded port, filesystem target, or registry target is visible in the supplied code; remote scan targets are runtime user input.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
268 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A PaperCut vulnerability discussed in a report about a pre-authentication remote code execution chain and patch bypasses. The excerpt does not identify this CVE's individual mechanism or map it to a specific watchTowr identifier. It references patches and bypasses but provides no affected versions, exploit availability, or observed exploitation.
An authentication bypass in PaperCut's Apache Tapestry page handling. Authorization checks applied to the root page but not additional authenticated pages invoked through the same service parameter. Exploited alongside CVE-2026-82078 for unauthenticated remote code execution. The initial 26.0.4 patch was subsequently bypassed.
A PaperCut authentication-bypass vulnerability that can be chained with CVE-2026-82078 to achieve pre-authentication remote code execution on a PaperCut application server.
An actively exploited PaperCut MF vulnerability that, when chained with CVE-2026-82078, permits unauthenticated settings modification and execution of malicious Java bytecode under the PaperCut server security context.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.