cbcvebase.
CVE-2026-82078
published 2026-08-28

CVE-2026-82078: An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database…

PriorityP183critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-09-14
Exploited in the wild
EPSS
1.69%
75.6th percentile
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.

Affected

7 ranges
VendorProductVersion rangeFixed in
papercutpapercut_mf< 24.1.924.1.9
papercutpapercut_mf>= 25.0.2 < 25.0.1225.0.12
papercutpapercut_mf>= 26.0.2 < 26.0.426.0.4
papercutpapercut_mf_ng< 24.1.10, 25.0.13, 26.0.524.1.10, 25.0.13, 26.0.5
papercutpapercut_ng< 24.1.924.1.9
papercutpapercut_ng>= 25.0.2 < 25.0.1225.0.12
papercutpapercut_ng>= 26.0.2 < 26.0.426.0.4

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck9.4CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.