deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

CISA-listed PaperCut NG/MF flaws chain into pre-auth code execution on print servers

CISA has listed two chained PaperCut NG/MF vulnerabilities that combine missing authentication with unsafe class loading, yielding pre-auth code execution on print servers that often run as SYSTEM.

CISA-listed PaperCut NG/MF flaws chain into pre-auth code execution on print servers

What happened

CISA added two PaperCut vulnerabilities to its Known Exploited Vulnerabilities catalog on 2026-08-31, with a federal remediation deadline of 2026-09-14 — a deadline that has since passed. According to a dev.to write-up citing the catalog, the entries cover CVE-2026-81578, which CISA describes as missing authentication for a critical function, and CVE-2026-82078, an unsafe reflection issue. Both affect PaperCut NG and PaperCut MF, widely deployed self-hosted print management software.

NVD scores the first at 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and characterises it as improper access control in the product's web management interface. The second is scored 9.1 and concerns unsafe dynamic class loading in the database connection utilities.

How the chain works

The two flaws complement each other. The access control bug lets unauthenticated requests reach management functionality in the web interface before authorisation is evaluated, making it the entry point. The class loading flaw is the payload path: the database connection utility instantiates a driver class named in configuration without validating it against an allowlist. An attacker who changes that configuration through the first flaw can then have the application load a class they control.

Although the second flaw's CVSS vector assumes an attacker already holds high privileges, the first flaw supplies the configuration access the second one needs. The result is code execution inside the print management service. On Windows deployments that service commonly runs as SYSTEM, which turns a print server into an unusually direct route deeper into the domain.

The campaign

Public reporting summarised in the dev.to post characterises the operation as an intrusion run by foreign agents, reaching hundreds of internet-exposed instances across dozens of countries within a short period, with education among the most affected sectors. The tooling observed was conventional for this kind of operation: credential extraction from memory and the registry, lateral movement using the stolen credentials, and directory database replication to collect account material.

The write-up argues that nothing here is technically novel. What set the campaign apart was throughput: once the entire chain is automatable and the list of exposed targets is public, the constraint on the operator becomes iteration speed rather than analyst headcount.

Patching and configuration checks

The core remediation is an upgrade to a fixed PaperCut NG/MF release. The vendor shipped emergency patches for the affected branches and later issued a further patch for systems that had already applied an earlier one, so administrators should confirm the currently recommended patch level rather than the first one published.

Patching alone is not the whole job, because the class loading flaw is reachable through the database connection settings. The dev.to post recommends reviewing the database driver configuration for values that do not correspond to a supported database, and checking the application's configuration files for driver or class names that no administrator set.

Investigation priorities

Because the chain leads to credentials, the write-up suggests prioritising the questions that follow from that: which accounts the service could read, whether administrative control of the host was achieved, whether credentials from that host were used elsewhere, and whether directory service accounts need rotation. Given the service's typical privilege level and domain membership, the credentials it holds are worth more than the print data it manages.

Retention matters as well. Attackers with administrative control can choose what the host records, so application and operating system logs should be exported to a system the PaperCut host cannot modify, and authentication records preserved long enough to answer questions about activity that ran weeks earlier.

Why it matters

Two flaws in a widely deployed, self-hosted service combine into pre-authentication code execution on servers that usually hold domain-relevant privilege, and exploitation is confirmed enough for a CISA catalog entry whose deadline has already elapsed. The campaign also illustrates a shift in intrusion economics: automation, not analyst hours, now scales compromise. For print-server administrators the practical takeaway is narrow but urgent — patch to the currently recommended level, verify the database driver configuration for anything unexplained, and treat any previously exposed host as a probable source of credential compromise rather than merely a print server.

  • #papercut
  • #cisa
  • #security
  • #patching
  • #print-servers

Related posts