cbcvebase.
CVE-2026-82077
published 2026-09-24

CVE-2026-82077: An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF…

PriorityP352high7.3CVSS 4.0
AVNACLATNPRHUINVCHVIHVAHSCNSINSANEPCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.74%
53.0th percentile
An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings.

Affected

2 ranges
VendorProductVersion rangeFixed in
papercutpapercut_ng_mf< 25.0.1325.0.13
papercutpapercut_ng_mf>= 26.0.0 < 26.0.526.0.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.