Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-82078

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 38.3%
CVSS Severity
CVSS v3 Score 9.1
Proposed Action
PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.
Ransomware Campaign
Unknown
Products affected by CVE-2026-82078


Contact Us

Shodan ® - All rights reserved