Help Ukraine, click for information

CVE-2026-82078

eb41dac7-0af8-4f84-9f6d-0272772514f4
CRITICAL
CVSS Score:9.1/10
Analyzed
Published: 8/28/2026
Modified: 9/14/2026
6 Affected Products
Risk Assessment
85%
Exploitability
100%
Impact
Overall Risk: 91%
Vulnerability Description

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.

CVSS v3.1 Score
9.1
CRITICAL
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
2.3
Exploitability
6
Impact
Attack Vector Analysis
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

> Thanks for visiting. Stay curious and stay secure. _