cbcvebase.
CVE-2026-87739
published 2026-09-24

CVE-2026-87739: An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report…

PriorityP343medium6.9CVSS 4.0
AVNACLATNPRNUINVCLVINVANSCLSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUYRXVXREXUX
EPSS
0.38%
29.6th percentile
An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and gain unauthorized access to sensitive information.

Affected

2 ranges
VendorProductVersion rangeFixed in
papercutpapercut_ng_mf< 25.0.1325.0.13
papercutpapercut_ng_mf>= 26.0.0 < 26.0.526.0.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.