DEV Community

OnaEiuspkz
OnaEiuspkz

Posted on

PaperCut CVE-2026-81578 and CVE-2026-82078: A Two-Flaw Chain That Ran at Agent Speed

PaperCut CVE-2026-81578 and CVE-2026-82078: A Two-Flaw Chain That Ran at Agent Speed

The two entries and the deadline

CISA added CVE-2026-81578 and CVE-2026-82078 to the Known Exploited Vulnerabilities catalog on 2026-08-31, both with a federal remediation deadline of 2026-09-14. The catalog names the first a missing authentication for critical function vulnerability and the second an unsafe reflection vulnerability, both in PaperCut NG/MF.
NVD rates CVE-2026-81578 at 9.8 with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H and describes an improper access control vulnerability in the web management interface of PaperCut MF and PaperCut NG. CVE-2026-82078 is rated 9.1 with the vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H and describes unsafe dynamic class loading in the database connection utilities, which is the part that turns a configuration change into executable code in the application process.

How the chain works and why the second flaw matters

The access control flaw allows unauthenticated requests to reach management functionality in the web interface before authorization is evaluated. The first flaw is the way in. The class loading flaw is the payload path: the database connection utility instantiates a driver class named in configuration without validating it against an allowlist. Change the configuration through the first flaw, and the second flaw then loads a class the attacker controls.
The result is code execution inside the paper management service. On Windows deployments this service commonly runs as SYSTEM, which makes the printing server an unusually direct route into the rest of the domain.

What made this campaign different

Public reporting on this campaign describes a foreign agent operated intrusion that reached hundreds of internet-exposed instances across dozens of countries in a short period, with education among the most affected sectors. The observed tooling is standard for this kind of operation: credential extraction from memory and the registry, lateral movement using the credentials obtained, and directory database replication to collect account material.
The distinguishing feature described in the reporting is not a novel technique. It is throughput. When the entire chain is automatable and the target list is public, the limiting factor becomes how quickly the operator can iterate rather than how many analysts it can employ.

Remediation and configuration verification

Upgrade to a fixed PaperCut NG/MF release. The vendor shipped emergency patches for the affected branches and later a further patch for systems that had already applied an earlier one, so confirm the currently recommended patch level rather than the first one published.
Then verify the configuration that the chain depends on. The class loading flaw is reachable through the database connection settings, so review the database driver configuration for values that do not correspond to a supported database, and check the application's configuration files for driver or class names that administrators did not set.

Investigation priorities

This chain leads to credentials. Prioritize the questions that follow from that: which accounts the service could read, whether administrative control over the host was achieved, whether credentials from the host were used elsewhere, and whether directory service accounts need rotation. Because the service commonly runs with high privilege and is joined to the domain, the credentials it holds are worth more than the print data it manages.
Retention matters as well. Attackers who obtain administrative control select what the host records. Export application and operating system logs to a system the PaperCut host cannot modify, and preserve authentication records for long enough to answer questions about a campaign that ran weeks ago.

Reading the reporting responsibly

Public accounts of this campaign describe tooling and outcomes rather than providing a complete intrusion narrative, and the number of affected organizations continues to be revised. What can be stated with confidence is narrower than the reporting and enough for planning: two flaws in a widely deployed self-hosted service can be chained into pre-authentication code execution, the service usually holds domain-relevant privilege, and the exploited list entry carries a deadline that has already passed.

References

Top comments (0)